---
id: CVE-2025-12177
title: >-
  The Download Manager plugin for WordPress is vulnerable to unauthorized access
  due to a hardcoded Cron key used in the deleteExpired() and
  clearTempDataCPCron() functions in all versions up to, and including, 3.3.30
summary: >-
  The Download Manager plugin for WordPress is vulnerable to unauthorized access
  due to a hardcoded Cron key used in the deleteExpired() and
  clearTempDataCPCron() functions in all versions up to, and including, 3.3.30.
  This makes it possib…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-321
published: '2025-11-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12177'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3390068%40download-manager&new=3390068%40download-manager&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/17d5253c-5000-40c7-a7fd-f75d4badfb5e?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00224
epssPercentile: 0.11967
ingestedAt: '2026-10-07T21:54:14.988Z'
---

## Overview

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
