nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-15364 CVE-2025-15364
HIGH
Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword
Record summary
CVE-2025-15364 has a selected CVSS score of 7.3 (high).
Description
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Download ManagerBrowse codename065 / Download ManagerDefault status: unaffected | CVE List | Through 3.3.40 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.40/src/__/Crypt.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3431915/download-manager wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/067031e8-6aa8-451c-a318-b1848c7a4f92?source=cve