The WordPress Download Manager plugin contains a vulnerability that allows attackers to obtain passwords for password-protected downloads by sending a specially crafted request to the validate-password API endpoint.
id: CVE-2023-6421
info:
name: WordPress Download Manager - File Password Exposure
author: ritik
...