CVE · High

CVE-2025-15364 — Download Manager [download-manager] < 3.3.41

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-15364 Download Manager [download-manager] < 3.3.41 Missing Support for Integrity Check High 7.3 < 3.3.41 3.3.41 2026-01-05

CVE-2025-15364

The Download Manager WordPress plugin has a security flaw in versions up to 3.3.40 that allows unauthorized users to modify certain account settings without proper verification of the user's identity. This vulnerability enables attackers to change non-administrator passwords, potentially leading to account takeover and unauthorized access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.