The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.
We have discovered 32,004 live websites that are affected by CVE-2026-14235.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 32,004 live websites (95% of Download Manager install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 253 versions ( 100% of all versions) |
| 6,618 websites | |
| 4,112 websites | |
| 4,080 websites | |
| 2,552 websites | |
| 1,491 websites | |
| 1,221 websites | |
| 1,012 websites | |
| 823 websites | |
| 625 websites | |
| 596 websites |
| .com | 10,806 websites |
| .de | 2,842 websites |
| .org | 2,724 websites |
| .it | 1,760 websites |
| .net | 1,003 websites |
| .jp | 881 websites |
| .nl | 680 websites |
| .fr | 662 websites |
| .co.uk | 502 websites |
| .co.jp | 496 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.pl | *,*** | ||
| *******.nagoya | *,*** | ||
| ************.org | *,*** | ||
| ***********.com | **,*** | ||
| ****.pt | **,*** | ||
| ******.com | **,*** | ||
| ***.**.uk | **,*** | ||
| *****.org | **,*** | ||
| **.******.com | **,*** | ||
| **********.com | **,*** |
FAQ