CVE-2025-60093: WordPress Download Manager Plugin <= 3.3.24 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager allows Cross Site Request Forgery. This issue affects Download Manager: from n/a through 3.3.24.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request Forgery.This issue affects Download Manager: from n/a through <= 3.3.24.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60093?
The severity level of CVE-2025-60093 is classified as high due to its ability to allow Cross-Site Request Forgery attacks.
How do I fix CVE-2025-60093?
To fix CVE-2025-60093, ensure you update Shahjada Download Manager or the WordPress Download Manager Plugin to version 3.3.25 or higher.
What versions are affected by CVE-2025-60093?
CVE-2025-60093 affects Shahjada Download Manager versions up to 3.3.24 and WordPress Download Manager Plugin versions up to 3.3.24.
What is Cross-Site Request Forgery in the context of CVE-2025-60093?
Cross-Site Request Forgery in CVE-2025-60093 is a vulnerability that allows an attacker to perform actions on behalf of a user without their consent.
Is there a specific workaround for CVE-2025-60093 before I can update?
While the most effective solution is to update, temporarily restricting access to the Download Manager or implementing CSRF tokens can mitigate the risk.