Impact
The vulnerability resides in the Download Manager plugin for WordPress, where the 'first_name' field is improperly processed in the suspension email template. This token injection flaw allows an attacker who has subscriber-level access or higher to manipulate the template, causing the plugin to expose the full Cookie header of an administrator’s active request. The exposed cookies include wordpress_logged_in_* session tokens, enabling the attacker to hijack the administrator’s session and take over the account. The flaw belongs to CWE-200, representing unauthorized disclosure of information.
Affected Systems
WordPress sites using the codename065 Download Manager plugin with a version of 3.3.71 or earlier are affected. No other version or vendor is listed as impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not on the CISA KEV list, suggesting no known widespread exploitation. The attacker must be authenticated at least as a subscriber and must target an account that an administrator can suspend. The exploit occurs during the administrator’s concurrent request that triggers the suspension email, so it requires a coordinated action: the attacker creates an account, the administrator suspends it, and the plugin’s template processing leaks the admin’s session cookies. While the attack vector is not trivial, the potential impact of full account takeover warrants careful countermeasures. The lack of public exploits and low EPSS suggest it is not a high‑volume threat yet, but the exposure of session tokens is critical.
OpenCVE Enrichment