CVE-2026-39676: WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Download Manager pluginto a version that resolves this vulnerability.Fixed in 3.3.52
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39676?
The severity of CVE-2026-39676 is classified as medium with a score of 5.3.
How do I fix CVE-2026-39676?
To fix CVE-2026-39676, update the Shahjada WordPress Download Manager plugin to the latest version.
What type of vulnerability is CVE-2026-39676?
CVE-2026-39676 is classified as a Broken Access Control vulnerability.
What versions of the plugin are affected by CVE-2026-39676?
CVE-2026-39676 affects Shahjada WordPress Download Manager versions from n/a to 3.3.52.
Can CVE-2026-39676 lead to data exposure?
CVE-2026-39676 may allow unauthorized access due to incorrectly configured access control levels.