CVE-2025-15364
Last modified
CVE-2025-15364 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-15364?
How severe is CVE-2025-15364?
How do I fix CVE-2025-15364?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-15357A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. Th…9.8
- CVE-2025-15358DVP-12SE11T - Denial of Service Vulnerability7.5
- CVE-2025-15359DVP-12SE11T - Out-of-bound memory write Vulnerability9.8
- CVE-2025-1536A vulnerability was found in Raisecom Multi-Service Intellig…7.3
- CVE-2025-15360A vulnerability was determined in newbee-mall-plus 2.0.0. Th…7.2
- CVE-2025-15363The Get Use APIs WordPress plugin before 2.0.10 executes im…5.9
- CVE-2025-15366The imaplib module, when passed a user-controlled command, c…5.9
- CVE-2025-15367The poplib module, when passed a user-controlled command, ca…5.9
- CVE-2025-15368The SportsPress plugin for WordPress is vulnerable to Local …8.8
- CVE-2025-15369The Xpro Addons — 140+ Widgets for Elementor plugin for Word…5.3
- CVE-2025-1537A vulnerability was found in Harpia DiagSystem 12. It has be…6.3
- CVE-2025-15370The Shield: Blocks Bots, Protects Users, and Prevents Securi…4.3
Are you affected by CVE-2025-15364?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
