Impact
An authorization bypass flaw lets an attacker send a crafted key to the Shahjada Download Manager plugin and retrieve embedded sensitive data, violating confidentiality. The weakness is a classic user‑controlled key issue classified as CWE‑639. The vulnerability does not allow code execution or denial of service, but it permits disclosure of data that the plugin may store for authorized users.
Affected Systems
WordPress sites running the Shahjada Download Manager plugin version 3.3.71 or older are affected. The vulnerability applies to all earlier releases from the first available version up to and including 3.3.71.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity risk. No EPSS score is available, and the issue is not listed in CISA KEV, suggesting that widespread active exploitation has not yet been documented. The likely attack vector is remote delivery of an HTTP request containing a user‑controlled key; no special privileges or additional software are required for exploitation. Consequently, any publicly accessible WordPress installation using a vulnerable plugin could be exposed to data disclosure.
OpenCVE Enrichment