CVE-2025-60092: WordPress Download Manager Plugin <= 3.3.25 - Sensitive Data Exposure Vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.24.
Other sources
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.25.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60092?
CVE-2025-60092 is classified as a medium severity vulnerability due to its potential for exposing sensitive system information.
How do I fix CVE-2025-60092?
To fix CVE-2025-60092, update Shahjada Download Manager or WordPress Download Manager Plugin to version 3.3.25 or later.
What impact does CVE-2025-60092 have on my system?
CVE-2025-60092 can allow unauthorized access to embedded sensitive data within the Download Manager.
Which versions are affected by CVE-2025-60092?
CVE-2025-60092 affects Shahjada Download Manager versions up to 3.3.24 and WordPress Download Manager Plugin versions up to 3.3.24.
Is CVE-2025-60092 being actively exploited?
As of the latest updates, there is no specific indication that CVE-2025-60092 is being actively exploited, but it is critical to apply the necessary updates promptly.