CVE · Medium

CVE-2025-13498 — Download Manager [download-manager] < 3.3.33

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13498 Download Manager [download-manager] < 3.3.33 Missing Authorization Medium 4.3 < 3.3.33 3.3.33 2025-12-17

CVE-2025-13498

The WordPress Download Manager plugin contains a security flaw that allows authorized users with minimal permissions to gain access to sensitive data. This vulnerability affects all versions up to 3.3.32 due to inadequate checks on certain AJAX requests, specifically the `wpdm_media_access` action. As a result, attackers can exploit this weakness to obtain passwords and access controls for restricted media files, potentially allowing them to bypass intended security measures and download protected content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.