Executive brief
The Download Manager plugin for WordPress, which is used to manage and track file downloads, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels, potentially leading to unauthorized modifications or access to download management features. Exploiting this could disrupt file management operations or allow attackers to manipulate how downloads are handled on the site.
Technical details
A missing authorization (CWE-862) vulnerability exists in the Shahjada Download Manager plugin for WordPress through version 3.3.52. The flaw stems from a failure to properly validate user permissions or security levels within the 'download-manager' component, leading to broken access control. An unauthenticated remote attacker can exploit this by interacting with affected endpoints to perform actions that should be restricted to higher-privileged users. The vulnerability was addressed in version 3.3.53. CVSS analysis indicates a partial impact on integrity or confidentiality depending on the specific configuration.
Affected products
- Shahjada (W3 Eden) Download Manager <= 3.3.52
Timeline
- 2026-01-20: other: Reported by researcher Steven Julian
- 2026-02-19: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE-2026-39676 published
- 2026-04-08: patched: Patch available in version 3.3.53