High severity7.5NVD Advisory· Published Mar 7, 2022· Updated Jun 17, 2026
CVE-2021-25087
CVE-2021-25087
Description
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<3.2.35+ 1 more
- (no CPE)range: <3.2.35
- (no CPE)range: 3.2.35
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/d7ceafae-65ec-4e05-9ed1-59470771bf07nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.