What is CVE-2026-14235?
CVE-2026-14235 affects The Download Manager WordPress plugin before 3.3.62, where temporary download tokens are not bound to the requesting session and do not expire promptly. This makes the token a long-lived, reusable bearer token, allowing an attacker with a leaked key to repeatedly download restricted files. Update the plugin to the latest version.
Azərbaycanca: CVE-2026-14235, əvvəl 3.3.62 versiyalı Download Manager WordPress plugin-də müvəqqəti yükləmə tokeni istifadəçi sessiyasına bağlanmır və vaxtında sönmür. Bu, sızmış token əldə edən hücumçuya təkrar yükləmə imkanı verir. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which product is affected by CVE-2026-14235 and what is the root cause?
This vulnerability affects The Download Manager WordPress plugin before version 3.3.62. The root cause is that temporary download tokens are not bound to the requesting session and do not expire promptly.
What can an attacker achieve by exploiting CVE-2026-14235?
An attacker with a leaked token can use it to repeatedly download restricted files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.