Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure

2025-12-17 00:00
type5afe

Strategic Overview

Status
Patched in 3.3.33
Affected PluginDownload Manager
Affected Version<= 3.3.32
CVSS4.3Medium
CVECVE-2025-13498
View all Download Manager vulnerabilities

Vulnerability Overview

The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.

Technical Analysis

REMEDIATION: Update to version 3.3.33, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C