Untriaged
Permalink
CVE-2026-39676
5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): NONE
WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.
References
Affected products
download-manager
- =<3.3.52
Matching in nixpkgs
pkgs.lomiri.lomiri-download-manager
Performs uploads and downloads from a centralized location
pkgs.lomiri-qt6.lomiri-download-manager
Performs uploads and downloads from a centralized location
Package maintainers
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>