VYPR
Medium severity5.3NVD Advisory· Published Apr 8, 2026· Updated Apr 29, 2026

CVE-2026-39676

CVE-2026-39676

Description

Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WordPress Download Manager plugin allows low-privileged users to access restricted functionality; update to 3.3.53.

Vulnerability

Description The CVE-2026-39676 vulnerability affects the WordPress Download Manager plugin (versions up to 3.3.52) and is due to a missing authorization check. This broken access control issue allows unprivileged users to execute actions that should require higher privileges, such as downloading or managing files they should not have access to [1].

Exploitation

Details Exploitation does not require authentication, but the attacker must be a user with some level of access (e.g., subscriber) to trigger the unauthorized action. The vulnerability is classified as low severity (CVSS 5.3) and is unlikely to be exploited individually, but it is known to be used in mass-exploit campaigns targeting thousands of WordPress sites [1].

Impact

Successful exploitation enables an attacker to perform actions like downloading protected files or modifying download settings, depending on the missing authorization scope. This can lead to data exposure or partial site compromise, though the impact is limited due to the low privilege escalation potential.

Mitigation

The vulnerability is patched in version 3.3.53. Users are strongly advised to update immediately. Patchstack customers can enable auto-updates for vulnerable plugins. If updating is not possible, consult a hosting provider for temporary workarounds [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.