Description
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata — including protected file references, role-based access restrictions, and password lock settings — into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Disclosure
Action: Patch Immediately
AI Analysis

Impact

The Download Manager plugin for WordPress contains an insecure direct object reference that only checks a global capability and a static NONCE key when handling the wpdm_duplicate parameter. It does not perform a per‑package authorization check. As a result, any authenticated user who has the ‘edit_posts’ capability or higher, such as a Contributor, can duplicate an arbitrary package owned by another user, including administrators. The clone copies all metadata, including protected file references, role‑based access restrictions, and password lock settings. The attacker can then edit the cloned package, remove those restrictions, and download files that were previously protected, thereby exposing sensitive content. Affected systems include installations of the codename065:Download Manager plugin for WordPress with versions up to and including 3.3.68. Any site running this plugin after the 3.3.68 release is potentially vulnerable. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated (Contributor or higher) and to have the ability to trigger the wpdm_duplicate action. Given these constraints, the risk is moderate, mainly due to the sensitive data exposure it permits.

Affected Systems

Codename065:Download Manager for WordPress, versions up to and including 3.3.68 on any WordPress site.

Risk and Exploitability

With a CVSS score of 6.5 and an EPSS probability of under 1%, the exploitation likelihood is low, though the impact of data exposure can be significant. Since the vulnerability is not listed in CISA’s KEV catalog, there are no known large‑scale exploit campaigns. The attack path requires authenticated membership of the ‘edit_posts’ capability, meaning non‑privileged users are not affected. However, if an attacker gains Contributor or higher, they can duplicate packages and remove protection, leading to potential data loss.

Generated by OpenCVE AI on September 19, 2026 at 20:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Download Manager plugin to version 3.3.69 or later, which includes a check that enforces object‑level authorization for duplication.
  • If an immediate upgrade is not possible, restrict non‑admin users by removing the ‘edit_posts’ capability or disabling contributors while the fix is pending.
  • Review and tighten role‑based permissions so that only administrators can duplicate or edit package metadata, closing the window for data exposure.

Generated by OpenCVE AI on September 19, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Codename065
Codename065 download Manager Plugin
Wordpress
Wordpress wordpress
Vendors & Products Codename065
Codename065 download Manager Plugin
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata — including protected file references, role-based access restrictions, and password lock settings — into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files.
Title Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Codename065 Download Manager Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T11:37:21.876Z

Reserved: 2026-09-16T16:34:40.641Z

Link: CVE-2026-92714

cve-icon Vulnrichment

Updated: 2026-09-18T11:37:15.594Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:52.133

Modified: 2026-09-18T13:23:37.403

Link: CVE-2026-92714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:41Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key