CVE-2026-14235
Received Received - Intake

Download Token Bypass in WordPress Download Manager

Vulnerability report for CVE-2026-14235, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: WPScan

Description

The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress Download Manager plugin before version 3.3.62. It allows unauthorized access to protected files because temporary download tokens are not tied to user sessions or expired promptly. Instead, tokens become long-lived, reusable, and portable, acting like a bearer token. If an attacker obtains a leaked token for a restricted file, they can download it repeatedly without further authentication.

Detection Guidance

To detect this vulnerability, check if your WordPress Download Manager plugin version is below 3.3.62. Inspect server logs for repeated unauthorized downloads of protected files using the same token. Look for tokens that remain valid across multiple sessions or IP addresses.

Impact Analysis

If you use the affected plugin version, an attacker who steals a download token could access your protected files without your knowledge. The token remains valid for about 10 uses or 11.5 days, allowing repeated unauthorized downloads of role-protected or password-locked files. This could lead to data breaches or unauthorized access to sensitive information.

Compliance Impact

This vulnerability could violate compliance requirements like GDPR or HIPAA by allowing unauthorized access to protected files. If sensitive data is exposed due to the flaw, it may result in non-compliance with data protection regulations, leading to legal penalties or reputational damage.

Mitigation Strategies

Immediately update the WordPress Download Manager plugin to version 3.3.62 or later. Review and revoke any exposed download tokens. Monitor for unauthorized access attempts and restrict access to sensitive files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14235. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart