Review
Download Manager
CVE published 2026-07-27
CVE-2026-14235
The Download Manager WordPress plugin before 3.3.62 has a vulnerability that allows unauthorized access to role- or password-protected package files. This is due to the plugin's temporary download token not being bound to the requesting session and not expiring promptly. As a result, an attacker who obtains a leaked download key can repeatedly download protected files without authorization. Users of the p [truncated]