Insecure Direct Object Reference in Download Manager Plugin for WordPress
CVE-2026-92714

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 September 2026

What is CVE-2026-92714?

The Download Manager plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability. This issue arises from improper verification during the duplication process, specifically the duplicate() function triggered on admin_init. The lack of object-level authorization checks allows authenticated attackers, with at least Author-level access, to duplicate Download Manager packages owned by other users, including administrators. This exploitation can lead to unauthorized access to sensitive package metadata, file references, and role-based access restrictions, as attackers can modify the cloned packages to remove security measures and download protected files.

Affected Version(s)

Download Manager 0 <= 3.3.68

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pb>sec
.