Description
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data.

This issue affects Download Manager: from n/a through 3.3.71.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure by unauthorized access
Action: Assess Impact
AI Analysis

Impact

An authorization bypass flaw lets an attacker send a crafted key to the Shahjada Download Manager plugin and retrieve embedded sensitive data, violating confidentiality. The weakness is a classic user‑controlled key issue classified as CWE‑639. The vulnerability does not allow code execution or denial of service, but it permits disclosure of data that the plugin may store for authorized users.

Affected Systems

WordPress sites running the Shahjada Download Manager plugin version 3.3.71 or older are affected. The vulnerability applies to all earlier releases from the first available version up to and including 3.3.71.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity risk. No EPSS score is available, and the issue is not listed in CISA KEV, suggesting that widespread active exploitation has not yet been documented. The likely attack vector is remote delivery of an HTTP request containing a user‑controlled key; no special privileges or additional software are required for exploitation. Consequently, any publicly accessible WordPress installation using a vulnerable plugin could be exposed to data disclosure.

Generated by OpenCVE AI on October 2, 2026 at 11:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Remove the Download Manager plugin from the WordPress installation to eliminate the exposure.
  • Restrict access to the plugin’s functions by using a web application firewall or access control rules to block unauthenticated requests that include the vulnerable key parameter.
  • Check for official plugin updates or patches from the vendor and apply them once available.

Generated by OpenCVE AI on October 2, 2026 at 11:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.
Title WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-02T11:30:53.569Z

Reserved: 2026-09-21T14:00:09.916Z

Link: CVE-2026-94405

cve-icon Vulnrichment

Updated: 2026-10-02T11:30:48.373Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:09.170

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-94405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T11:45:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key