Insecure Direct Object Reference in Download Manager Plugin for WordPress
CVE-2026-92714
6.5MEDIUM
What is CVE-2026-92714?
The Download Manager plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability. This issue arises from improper verification during the duplication process, specifically the duplicate() function triggered on admin_init. The lack of object-level authorization checks allows authenticated attackers, with at least Author-level access, to duplicate Download Manager packages owned by other users, including administrators. This exploitation can lead to unauthorized access to sensitive package metadata, file references, and role-based access restrictions, as attackers can modify the cloned packages to remove security measures and download protected files.
Affected Version(s)
Download Manager 0 <= 3.3.68