The WordPress Download Manager plugin contains a vulnerability that allows attackers to obtain passwords for password-protected downloads by sending a specially crafted request to the validate-password API endpoint.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view