Access violation vulnerability in Download Manager 3.3.32

The Download Manager plugin for WordPress has a security vulnerability that allows unauthorized access to important information. This vulnerability exists in all versions up to and including 3.3.32. The issue is caused by a lack of proper authorization and capability checks on the `wpdm_media_access` action. This means that attackers who are logged in with Subscriber-level access or higher can retrieve passwords and access control settings for protected media attachments. They can then use this information to bypass the intended protection and download restricted files.

Detected in:

Download Manager fixed vulnerable versions: >= * <= 3.3.32
Download Manager Pro fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.