CVE · High

CVE-2021-25087 — Download Manager [download-manager] < 3.2.25

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-25087 Download Manager [download-manager] < 3.2.25 Missing Authorization High 7.5 < 3.2.35 3.2.35 2022-02-02

CVE-2021-25087

The Download Manager plugin for WordPress versions prior to 3.2.25 lacks proper authorization validation on certain REST API endpoints, permitting unauthenticated users to access them. This vulnerability enables attackers to retrieve sensitive data including post passwords and the files Master Key without requiring valid credentials. The flaw was remedied in version 3.2.25 for the Master Key exposure and version 3.2.24 for the password disclosure issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.