๐Ÿ” CVE Alert

CVE-2026-14235

UNKNOWN 0.0

WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.

Vendor unknown
Product download manager
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown download manager

Be the first to know when new unknown vulnerabilities affecting unknown download manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Download Manager
0 < 3.3.62

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/9634b51c-59a1-45f6-8b09-421d6bfd0204/

Credits

Alessandro Greco aka Aleff Giovanbattista Ianni (University of Calabria - UNICAL) WPScan