CVE-2023-6785
The WordPress Download Manager plugin prior to version 3.2.85 contains an access control vulnerability that allows unauthenticated or low-privileged users to perform actions restricted to higher-privileged roles due to missing authorization checks and nonce validation. The flaw was identified by wesley (wcraft) and stems from insufficient verification mechanisms in a plugin function. Users should upgrade to version 3.2.85 or later to resolve this issue.
Based on public CVE data (MITRE/NVD).