The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.
History

Mon, 27 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Downloadmanager
Downloadmanager download Manager
Wordpress
Wordpress wordpress
Vendors & Products Downloadmanager
Downloadmanager download Manager
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.
Title WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-27T06:00:04.830Z

Reserved: 2026-06-30T12:55:00.420Z

Link: CVE-2026-14235

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-27T09:15:12Z