PT-2026-1363 · WordPress · Download Manager

·

CVE-2025-15364

·

Publicado

2026-01-06

·

Atualizado

2026-01-06

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Download Manager plugin for WordPress versions prior to 3.3.41
Description The Download Manager plugin for WordPress is susceptible to privilege escalation, potentially leading to account takeover. The issue stems from insufficient user identity validation before allowing updates to user details, such as passwords. This allows unauthenticated attackers to modify user passwords—excluding those of administrators—and subsequently gain access to their accounts.
Recommendations Update the Download Manager plugin to version 3.3.41 or later.

Correção

LPE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15364

Produtos afetados

Download Manager