Impact
The Download Manager plugin for WordPress contains an insecure direct object reference that only checks a global capability and a static NONCE key when handling the wpdm_duplicate parameter. It does not perform a per‑package authorization check. As a result, any authenticated user who has the ‘edit_posts’ capability or higher, such as a Contributor, can duplicate an arbitrary package owned by another user, including administrators. The clone copies all metadata, including protected file references, role‑based access restrictions, and password lock settings. The attacker can then edit the cloned package, remove those restrictions, and download files that were previously protected, thereby exposing sensitive content. Affected systems include installations of the codename065:Download Manager plugin for WordPress with versions up to and including 3.3.68. Any site running this plugin after the 3.3.68 release is potentially vulnerable. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated (Contributor or higher) and to have the ability to trigger the wpdm_duplicate action. Given these constraints, the risk is moderate, mainly due to the sensitive data exposure it permits.
Affected Systems
Codename065:Download Manager for WordPress, versions up to and including 3.3.68 on any WordPress site.
Risk and Exploitability
With a CVSS score of 6.5 and an EPSS probability of under 1%, the exploitation likelihood is low, though the impact of data exposure can be significant. Since the vulnerability is not listed in CISA’s KEV catalog, there are no known large‑scale exploit campaigns. The attack path requires authenticated membership of the ‘edit_posts’ capability, meaning non‑privileged users are not affected. However, if an attacker gains Contributor or higher, they can duplicate packages and remove protection, leading to potential data loss.
OpenCVE Enrichment