cvedb.io
CVE-2026-14235
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-07-27T07:16:25.700 · Last modified 2026-07-27T15:16:48.403

Summary

The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.