Description
The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the administrator's full Cookie header, including wordpress_logged_in_* session cookies, from the suspension email sent during the administrator's authenticated request, enabling full session hijack and account takeover. Exploitation requires an administrator to perform the Suspend action against the attacker's account, which causes the plugin to synchronously compile and send the suspension email inside the administrator's authenticated HTTP request — making the administrator's session cookies available to the template engine at send time.
Published: 2026-10-10
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Exposure leading to session hijack and account takeover
Action: Patch immediately
AI Analysis

Impact

The vulnerability resides in the Download Manager plugin for WordPress, where the 'first_name' field is improperly processed in the suspension email template. This token injection flaw allows an attacker who has subscriber-level access or higher to manipulate the template, causing the plugin to expose the full Cookie header of an administrator’s active request. The exposed cookies include wordpress_logged_in_* session tokens, enabling the attacker to hijack the administrator’s session and take over the account. The flaw belongs to CWE-200, representing unauthorized disclosure of information.

Affected Systems

WordPress sites using the codename065 Download Manager plugin with a version of 3.3.71 or earlier are affected. No other version or vendor is listed as impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not on the CISA KEV list, suggesting no known widespread exploitation. The attacker must be authenticated at least as a subscriber and must target an account that an administrator can suspend. The exploit occurs during the administrator’s concurrent request that triggers the suspension email, so it requires a coordinated action: the attacker creates an account, the administrator suspends it, and the plugin’s template processing leaks the admin’s session cookies. While the attack vector is not trivial, the potential impact of full account takeover warrants careful countermeasures. The lack of public exploits and low EPSS suggest it is not a high‑volume threat yet, but the exposure of session tokens is critical.

Generated by OpenCVE AI on October 10, 2026 at 05:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Download Manager plugin to version 3.3.72 or later, which resolves the token injection in suspension emails.
  • Restrict the ‘Suspend’ functionality or limit subscriber-level accounts from triggering email templates that include sensitive session data.
  • Implement a web application firewall rule to detect and block improper usage of token placeholders in email templates, preventing the leak of authentication cookies.

Generated by OpenCVE AI on October 10, 2026 at 05:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the administrator's full Cookie header, including wordpress_logged_in_* session cookies, from the suspension email sent during the administrator's authenticated request, enabling full session hijack and account takeover. Exploitation requires an administrator to perform the Suspend action against the attacker's account, which causes the plugin to synchronously compile and send the suspension email inside the administrator's authenticated HTTP request — making the administrator's session cookies available to the template engine at send time.
Title Download Manager <= 3.3.71 - Authenticated (Subscriber+) Sensitive Information Exposure via Email Template Token Injection in 'first_name' Profile Field Token Injection into Suspension Email
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:45.587Z

Reserved: 2026-10-01T15:36:47.334Z

Link: CVE-2026-103964

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:39.257

Modified: 2026-10-10T05:16:39.257

Link: CVE-2026-103964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor