CVE-2025-13498
The WordPress Download Manager plugin contains a security flaw that allows authorized users with minimal permissions to gain access to sensitive data. This vulnerability affects all versions up to 3.3.32 due to inadequate checks on certain AJAX requests, specifically the `wpdm_media_access` action. As a result, attackers can exploit this weakness to obtain passwords and access controls for restricted media files, potentially allowing them to bypass intended security measures and download protected content.
Based on public CVE data (MITRE/NVD).