Sceawere

Vulnerability Detail

CVE-2026-103964UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Download Manager Sensitive Information Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
codename065
Product
Download Manager
Attack Type
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the administrator's full Cookie header, including wordpress_logged_in_* session cookies, from the suspension email sent during the administrator's authenticated request, enabling full session hijack and account takeover. Exploitation requires an administrator to perform the Suspend action against the attacker's account, which causes the plugin to synchronously compile and send the suspension email inside the administrator's authenticated HTTP request — making the administrator's session cookies available to the template engine at send time.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-10T05:16:39.257Z",
  "pubdate": "2026-10-10T05:16:39.257Z",
  "executiveSummary": "The Download Manager plugin for WordPress is susceptible to a critical Sensitive Information Exposure vulnerability affecting versions 3.3.71 and earlier.\nThis flaw allows authenticated attackers with subscriber-level privileges or higher to exfiltrate an administrator's full Cookie header, including active 'wordpress_logged_in_*' session tokens.\nThe vulnerability occurs because the plugin synchronously processes email templates containing the administrator's session context during the suspension of a user account.\nSuccessful exploitation enables full session hijacking and unauthorized account takeover of administrator profiles.\nThe attack requires an administrator to actively perform a suspension action against an attacker-controlled account, which triggers the inclusion of sensitive server-side session data into the outgoing email notification.\nThis vulnerability represents a high-risk security flaw as it facilitates total privilege escalation through the bypass of authentication mechanisms.",
  "technicalDetails": "The vulnerability resides within the user management and email notification components of the Download Manager plugin. The root cause is the insecure handling of the 'first_name' parameter during the composition of account suspension emails.\nWhen an administrator triggers the suspension of a user account, the plugin initiates a synchronous execution flow to compile the suspension email notification. Due to improper input handling and template variable exposure, the plugin's template engine inadvertently includes the active environment's global variables and request headers within the email body.\nSpecifically, the 'first_name' parameter, which is user-controlled, facilitates the injection or redirection of the template engine to access context variables that contain the current user's HTTP request headers.\nThe attack flow proceeds as follows: 1) An attacker with at least subscriber-level access crafts a malicious profile or interaction that leverages the 'first_name' parameter. 2) The attacker baits or waits for an administrator to perform the 'Suspend' action on the attacker's account. 3) Upon the administrator's request to suspend the user, the plugin synchronously triggers the email generation process. 4) The plugin's template engine populates the notification email with the administrator's sensitive session data, including the 'wordpress_logged_in_*' cookie, as it is present within the administrator's authenticated session context at the moment of execution. 5) The resulting email, containing the hijacked session cookies, is dispatched to an email address accessible to the attacker.\nBecause the email construction occurs within the synchronous context of the administrator's authenticated HTTP request, the sensitive session tokens are treated as available variables. The impact of this information disclosure is severe, as the possession of valid session cookies allows the attacker to bypass standard login authentication, effectively assuming the administrator's identity and maintaining persistent, unauthorized access to the WordPress dashboard and underlying system settings. This interaction does not require external network exposure beyond the standard WordPress administrative interface, as the exploitation is driven by the internal plugin logic during legitimate administrative actions."
}
CVE-2026-103964: Download Manager Sensitive Information Exposure (MEDIUM Severity, CVSS: 4.3) | Sceawere