CVE-2026-14235

WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key

The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.


We have discovered 32,004 live websites that are affected by CVE-2026-14235.

Run a Free Instant Scan




Affected Software

Product  Download Manager
Category Wordpress Plugins
Vulnerable Domains32,004 live websites (95% of Download Manager install base)
Vulnerable Versions
  • from 0 through 3.3.62
Vulnerable Versions Count253 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • Alessandro Greco aka Aleff (finder)
  • Giovanbattista Ianni (University of Calabria - UNICAL) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14235
United States6,618 websites



Germany4,112 websites
Japan4,080 websites
Italy2,552 websites
France1,491 websites
GB1,221 websites
Spain1,012 websites
Netherlands823 websites
Poland625 websites
Brazil596 websites

Website Distribution by TLD

Number of websites using CVE-2026-14235
.com10,806 websites
.de2,842 websites
.org2,724 websites
.it1,760 websites
.net1,003 websites
.jp881 websites
.nl680 websites
.fr662 websites
.co.uk502 websites
.co.jp496 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14235

Top websites that are affected by CVE-2026-14235. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.pl Poland*,***
*******.nagoya Japan*,***
************.org United States*,***
***********.com Netherlands**,***
****.pt Portugal**,***
******.com United States**,***
***.**.uk GB**,***
*****.org United States**,***
**.******.com United States**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2026-14235 is Improper Access Control in Download Manager
A total of 32,004 websites have been identified as vulnerable to CVE-2026-14235, based on global website indexing conducted by WebTechSurvey.
The Download Manager is affected by the CVE-2026-14235 vulnerability.
Download Manager versions up to 3.3.62 are vulnerable to CVE-2026-14235.
CVE-2026-14235 is resolved in version 3.3.62 of Download Manager.