CVE-2025-15364
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15364 is a privilege escalation via account takeover vulnerability in the Download Manager plugin for WordPress, affecting all versions up to and including 3.3.40. The flaw allows unauthenticated attackers to change the passwords of non-administrator users and take over their accounts. It was published on January 5–6, 2026, and was reported by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (Wordfence, NVD).

Technical details

The root cause is classified as CWE-353 (Missing Support for Integrity Check): the plugin's Crypt.php component fails to properly validate a user's identity before allowing updates to sensitive account details such as passwords. Because no authentication or integrity verification is enforced on the password-update flow, a remote, unauthenticated attacker can submit crafted requests to reset any non-administrator user's password. The vulnerable code path is visible in the plugin source at src/__/Crypt.php#L18 in version 3.3.40, and the fix was introduced in changeset 3431915 (Wordfence, WP Trac - Vulnerable Code, WP Trac - Patch).

Impact

Successful exploitation allows an unauthenticated attacker to reset the password of any non-administrator WordPress user account and gain full access to that account. This can lead to unauthorized access to protected downloads, sensitive user data, and any content or capabilities associated with the compromised account. Depending on the privileges of the targeted user (e.g., editors, authors, or subscribers with elevated roles), attackers could further escalate access, inject malicious content, or use the compromised account as a foothold for lateral movement within the WordPress environment (Wordfence).

Exploitability

The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable over the network. The EPSS score is approximately 0.025% (0.000250), indicating a currently low probability of active exploitation in the wild. No public PoC exploit code, exploit kit integration, or confirmed in-the-wild exploitation has been reported as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, NVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Download Manager plugin (version ≤ 3.3.40) using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/download-manager/readme.txt.
  2. Enumerate target users: Identify non-administrator WordPress usernames via the REST API (/wp-json/wp/v2/users), login error messages, or author archive pages.
  3. Craft malicious request: Send a crafted HTTP request to the plugin's password-update endpoint, supplying the target username or user ID without valid authentication credentials, exploiting the missing identity validation in Crypt.php.
  4. Reset target password: The plugin processes the request without verifying the requester's identity, updating the target user's password to the attacker-supplied value.
  5. Account takeover: Log in to the WordPress site using the target user's credentials, gaining access to their account, protected downloads, and any associated privileges (Wordfence, WP Trac - Vulnerable Code).

Indicators of compromise

  • Network: Unexpected POST requests to Download Manager plugin endpoints (e.g., paths containing download-manager or wpdm) from unauthenticated or unknown IP addresses, particularly those targeting password-reset or account-update functionality.
  • Logs: WordPress access logs showing unauthenticated requests to plugin-specific AJAX actions or REST endpoints associated with user account updates; repeated requests from a single IP targeting multiple usernames.
  • Logs: WordPress authentication logs (wp-login.php) showing successful logins from unfamiliar IP addresses for non-administrator accounts shortly after anomalous plugin endpoint activity.
  • File System: No direct file system artifacts expected from exploitation alone, but post-compromise activity may include new or modified files if the attacker uses the hijacked account to upload content.
  • Process/Behavior: Unusual content changes, new posts, or file uploads attributed to non-administrator user accounts that the legitimate user did not perform.

Mitigation and workarounds

Site administrators should update the Download Manager plugin to version 3.3.41 or later, which includes the fix introduced in changeset 3431915 that adds proper identity validation before allowing password updates (WP Trac - Patch). If an immediate update is not possible, consider temporarily deactivating the plugin to eliminate the attack surface. Additionally, review WordPress user accounts for unauthorized password changes or suspicious login activity, and enforce strong, unique passwords for all non-administrator accounts as a compensating control (Wordfence).

Community reactions

Wordfence disclosed the vulnerability and published it in their threat intelligence database, noting it as a network-accessible issue requiring no privileges or user interaction. The vulnerability was included in Wordfence's weekly WordPress vulnerability report for January 5–11, 2026, and was also referenced in CISA's vulnerability bulletin for the week of January 5, 2026. Sucuri included it in their January 2026 vulnerability patch roundup, and RedPacket Security amplified the disclosure on social media (Wordfence Blog, Sucuri Blog, CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NoYesAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NoYesAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NoNoAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NoYesAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management