Executive brief
The Download Manager plugin for WordPress, which is used to manage and track file downloads, contains a security flaw in how it handles access tokens. When a user is authorized to download a protected file, the system generates a temporary key that is not properly tied to that specific user's session and does not expire quickly. If this key is leaked—such as through browser history, server logs, or shared links—an unauthorized person can use it to repeatedly download protected files without needing a password or the correct user permissions.
Technical details
The Download Manager plugin suffers from an improper authorization vulnerability due to the use of long-lived, multi-use, and portable bearer tokens (_wpdmkey). The tokens are stored with a deviceID of 'alldevice' and are looked up by token name only, rather than being bound to a specific user session or IP address. An attacker who obtains a leaked download key (e.g., via Referer headers, proxy logs, or browser history) can bypass role-based or password-protected access controls to download package files. The vulnerability exists in versions prior to 3.3.62, where the default token lifetime was approximately 11.5 days and allowed up to 10 uses. The issue is addressed in version 3.3.62.
Affected products
- WPDM Download Manager before 3.3.62
Timeline
- 2026-07-06: disclosed: Initial public disclosure by researchers
- 2026-07-27: advisory: NVD publication date