CVE · Medium

CVE-2025-60092 — Download Manager [download-manager] < 3.3.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-60092 Download Manager [download-manager] < 3.3.26 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 5.3 < 3.3.26 3.3.26 2025-09-26

CVE-2025-60092

The Download Manager plugin for WordPress contains a flaw that allows unauthorized individuals to access confidential information without requiring authentication, affecting all versions prior to 3.3.26.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.