CVE-2025-63070: WordPress Download Manager plugin <= 3.3.32 - Sensitive Data Exposure vulnerability
Published Dec 9, 2025
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32.
Affected Software
2 affected components
Shahjada Download Manager<=3.3.32
wordpress/download-manager<=3.3.32
Event History
Dec 9, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-63070?
CVE-2025-63070 is classified as a high-severity vulnerability due to the exposure of sensitive data.
2
How do I fix CVE-2025-63070?
To resolve CVE-2025-63070, upgrade the Shahjada Download Manager to version 3.3.33 or later.
3
What systems are affected by CVE-2025-63070?
CVE-2025-63070 affects Shahjada Download Manager versions up to and including 3.3.32.
4
What data is exposed in CVE-2025-63070?
CVE-2025-63070 allows unauthorized retrieval of embedded sensitive data within the application.
5
Is my website vulnerable if I use the affected version of Shahjada Download Manager?
Yes, if you are using Shahjada Download Manager version 3.3.32 or earlier, your website is vulnerable to CVE-2025-63070.