CVE-2026-103964
Received Received - Intake

Sensitive Information Exposure in WordPress Download Manager Plugin

Vulnerability report for CVE-2026-103964, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the administrator's full Cookie header, including wordpress_logged_in_* session cookies, from the suspension email sent during the administrator's authenticated request, enabling full session hijack and account takeover. Exploitation requires an administrator to perform the Suspend action against the attacker's account, which causes the plugin to synchronously compile and send the suspension email inside the administrator's authenticated HTTP request β€” making the administrator's session cookies available to the template engine at send time.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
codename065 Download Manager 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Download Manager plugin for WordPress has a vulnerability that allows sensitive information exposure. Authenticated attackers with subscriber-level access or higher can extract an administrator's full Cookie header, including session cookies, from a suspension email sent during an administrator's request. This enables session hijacking and account takeover if an administrator suspends the attacker's account.

Detection Guidance

To detect this vulnerability, monitor for unauthorized access attempts or suspicious activity related to the Download Manager plugin. Check WordPress logs for suspension email requests containing sensitive cookie data. Inspect network traffic for unusual outbound requests from the plugin.

Impact Analysis

If you use the Download Manager plugin in WordPress with versions up to 3.3.71, an attacker with subscriber access could steal your administrator's session cookies. This allows them to hijack the administrator's session, take over their account, and gain full control of your WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. A breach may result in legal penalties, loss of trust, and reputational damage due to compromised user sessions and data exposure.

Mitigation Strategies

Immediately update the Download Manager plugin to the latest version beyond 3.3.71. If an update is not available, consider disabling the plugin until a patch is released. Review user roles and restrict subscriber-level access to only necessary functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103964. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart