---
id: CVE-2025-15364
title: >-
  The Download Manager plugin for WordPress is vulnerable to privilege
  escalation via account takeover in all versions up to, and including, 3.3.40
summary: >-
  The Download Manager plugin for WordPress is vulnerable to privilege
  escalation via account takeover in all versions up to, and including, 3.3.40.
  This is due to the plugin not properly validating a user's identity prior to
  updating thei…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-353
published: '2026-01-06'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15364'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.40/src/__/Crypt.php#L18
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3431915/download-manager#file7
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/067031e8-6aa8-451c-a318-b1848c7a4f92?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00195
epssPercentile: 0.08262
ingestedAt: '2026-09-30T22:27:27.700Z'
---

## Overview

The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
