Sceawere
Vulnerability Detail
CVE-2026-94405UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Download Manager Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 13h ago
- Vendor
- Shahjada
- Product
- Download Manager
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T10:17:09.170Z",
"pubdate": "2026-10-02T10:17:09.170Z",
"executiveSummary": "The Download Manager plugin for WordPress, specifically versions n/a through 3.3.71, is susceptible to an Authorization Bypass vulnerability.\nThis vulnerability is rooted in the improper handling of user-controlled keys, which allows unauthenticated or unauthorized attackers to gain access to restricted, sensitive data embedded within the application.\nThe core issue involves insufficient validation of security tokens or identifiers passed through input parameters, effectively bypassing intended access control mechanisms.\nThe impact of successful exploitation is significant, as it facilitates the unauthorized retrieval of sensitive information that should be protected by the plugin's access management logic.\nThe attack does not explicitly require prior authentication, making it a critical risk for systems utilizing this plugin to manage private or sensitive file downloads.\nExploitation allows an attacker to bypass server-side authorization checks by manipulating the input parameters used to identify or verify file access, leading to unauthorized data disclosure and potential exposure of proprietary or private infrastructure data.",
"technicalDetails": "The vulnerability originates from a flawed implementation of authorization checks within the Download Manager plugin (versions n/a through 3.3.71).\nThe root cause is an Authorization Bypass Through User-Controlled Key, where the application fails to adequately verify the authenticity or ownership of specific input parameters used to retrieve sensitive objects or data paths.\nIn typical operation, the plugin is expected to validate that a requestor possesses sufficient authorization—often represented by a cryptographically signed key or a valid session identifier—before fulfilling a request for embedded sensitive data.\nHowever, due to insecure input handling, an attacker can craft a request that includes a manipulated or predictable key parameter. The backend code fails to perform a rigorous server-side check against the session or access control list (ACL) associated with the resource.\nInstead, the vulnerable component blindly trusts the user-supplied input to facilitate the retrieval process.\nThe attack flow follows these steps: 1. The attacker identifies the endpoint responsible for serving embedded sensitive content. 2. The attacker observes that the request relies on a user-controlled parameter to determine access permissions. 3. By manipulating this parameter, the attacker bypasses the authorization logic that is meant to block unauthorized requests. 4. The server processes the malicious input and returns the requested sensitive data, which the attacker then exfiltrates.\nThis vulnerability is particularly dangerous because it bypasses standard WordPress permission hooks if the plugin does not correctly implement current_user_can() checks or equivalent verification logic before accessing the data store.\nSince the vulnerability pertains to the input processing layer, it functions independently of existing WordPress user roles if the check is completely absent or fails to validate the user context entirely.\nThe post-exploitation impact includes the potential for large-scale enumeration of sensitive files, leakage of server-side configuration data, or access to private user information stored in the plugin's database.\nBecause the vulnerability operates over standard web protocols (HTTP/HTTPS), it requires no specialized network configuration, and the attack surface is limited only by the visibility of the vulnerable file retrieval endpoints."
}