CVE-2014-8585

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
04/11/2014
Last modified:
12/04/2025

Description

Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:w3eden:download_manager:1.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.2.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.2.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.2.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.2.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.2.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.5.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.5.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.5.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.5.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:w3eden:download_manager:1.5.32:*:*:*:*:wordpress:*:*