PatchSiren

Download Manager CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Download Manager CVE published 2026-07-27

CVE-2026-14235

The Download Manager WordPress plugin before 3.3.62 has a vulnerability that allows unauthorized access to role- or password-protected package files. This is due to the plugin's temporary download token not being bound to the requesting session and not expiring promptly. As a result, an attacker who obtains a leaked download key can repeatedly download protected files without authorization. Users of the p [truncated]