The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 08 Nov 2025 03:45:00 +0000

Type Values Removed Values Added
Description The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.
Title Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-11-08T03:27:45.992Z

Reserved: 2025-10-24T15:57:21.778Z

Link: CVE-2025-12177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-08T04:15:45.033

Modified: 2025-11-08T04:15:45.033

Link: CVE-2025-12177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.