MEDIUM
codename065
CVE published 2026-09-18
CVE-2026-92714
The Download Manager plugin for WordPress has a vulnerability allowing authenticated attackers with Author-level access to duplicate arbitrary packages owned by other users. This could potentially lead to unauthorized file downloads and access to sensitive information. WordPress administrators and users with Author-level access should verify their exposure and update the plugin to mitigate the risk. The v [truncated]