
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15364 is a privilege escalation via account takeover vulnerability in the Download Manager plugin for WordPress, affecting all versions up to and including 3.3.40. The flaw allows unauthenticated attackers to change the passwords of non-administrator users and take over their accounts. It was published on January 5–6, 2026, and was reported by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (Wordfence, NVD).
The root cause is classified as CWE-353 (Missing Support for Integrity Check): the plugin's Crypt.php component fails to properly validate a user's identity before allowing updates to sensitive account details such as passwords. Because no authentication or integrity verification is enforced on the password-update flow, a remote, unauthenticated attacker can submit crafted requests to reset any non-administrator user's password. The vulnerable code path is visible in the plugin source at src/__/Crypt.php#L18 in version 3.3.40, and the fix was introduced in changeset 3431915 (Wordfence, WP Trac - Vulnerable Code, WP Trac - Patch).
Successful exploitation allows an unauthenticated attacker to reset the password of any non-administrator WordPress user account and gain full access to that account. This can lead to unauthorized access to protected downloads, sensitive user data, and any content or capabilities associated with the compromised account. Depending on the privileges of the targeted user (e.g., editors, authors, or subscribers with elevated roles), attackers could further escalate access, inject malicious content, or use the compromised account as a foothold for lateral movement within the WordPress environment (Wordfence).
The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable over the network. The EPSS score is approximately 0.025% (0.000250), indicating a currently low probability of active exploitation in the wild. No public PoC exploit code, exploit kit integration, or confirmed in-the-wild exploitation has been reported as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, NVD).
https://target.com/wp-content/plugins/download-manager/readme.txt./wp-json/wp/v2/users), login error messages, or author archive pages.Crypt.php.download-manager or wpdm) from unauthenticated or unknown IP addresses, particularly those targeting password-reset or account-update functionality.wp-login.php) showing successful logins from unfamiliar IP addresses for non-administrator accounts shortly after anomalous plugin endpoint activity.Site administrators should update the Download Manager plugin to version 3.3.41 or later, which includes the fix introduced in changeset 3431915 that adds proper identity validation before allowing password updates (WP Trac - Patch). If an immediate update is not possible, consider temporarily deactivating the plugin to eliminate the attack surface. Additionally, review WordPress user accounts for unauthorized password changes or suspicious login activity, and enforce strong, unique passwords for all non-administrator accounts as a compensating control (Wordfence).
Wordfence disclosed the vulnerability and published it in their threat intelligence database, noting it as a network-accessible issue requiring no privileges or user interaction. The vulnerability was included in Wordfence's weekly WordPress vulnerability report for January 5–11, 2026, and was also referenced in CISA's vulnerability bulletin for the week of January 5, 2026. Sucuri included it in their January 2026 vulnerability patch roundup, and RedPacket Security amplified the disclosure on social media (Wordfence Blog, Sucuri Blog, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."