CVE · Medium

CVE-2025-63070 — Download Manager [download-manager] < 3.3.33

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-63070 Download Manager [download-manager] < 3.3.33 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 4.3 < 3.3.33 3.3.33 2025-09-30

CVE-2025-63070

Authenticated users with a minimum of subscriber permissions can potentially retrieve confidential information from the Download Manager plugin's database through an unidentified security flaw present in all versions prior to 3.3.32. This vulnerability exposes sensitive user or configuration details, allowing unauthorized access to critical system settings and possibly user credentials. The exposure affects any version up to 3.3.32.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.