CVE-2024-8031 Information
May 16, 2025
cve
Description
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers with admin-level access and above to download arbitrary files that may contain sensitive information like wp-config.php.
Reference
https://wpscan.com/vulnerability/c6f54e6f-0a50-424f-ae3a-00b9880d9f13/
Share on: