The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codename065
Codename065 download Manager Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Codename065
Codename065 download Manager Plugin Wordpress Wordpress wordpress |
Tue, 06 Jan 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account. | |
| Title | Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword | |
| Weaknesses | CWE-353 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-06T01:50:12.652Z
Updated: 2026-01-06T18:57:23.139Z
Reserved: 2025-12-30T14:21:41.555Z
Link: CVE-2025-15364
Updated: 2026-01-06T14:20:11.535Z
Status : Awaiting Analysis
Published: 2026-01-06T02:15:41.193
Modified: 2026-01-08T18:09:23.230
Link: CVE-2025-15364
No data.