OVERVIEW CVE-2026-4057 affects the Download Manager plugin for WordPress through version 3.3.51. The vulnerability exists in the makeMediaPublic() and makeMediaPrivate() functions, which lack proper capability checks to verify post ownership. This allows authenticated users to modify access controls on media files they do not own. SEVERITY This vulnerability carries a CVSS 3.1 score of 4.3 (Medium), with a network-based attack vector requiring low complexity and low privileges (Contributor-level access or above). The impact is limited to integrity violations, as attackers can strip protection metadata including passwords, access restrictions, and private flags from media files, potentially exposing admin-protected content via direct URLs. There is no confidentiality or availability impact. EXPLOITATION STATUS The vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and is not on any active hot lists. The EPSS score of 0.0001 indicates minimal real-world exploitation likelihood. Community attention appears limited, suggesting low visibility in the threat landscape at this time. No public exploit code has been widely reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Codename065 | Download Manager | >= 0, <= 3.3.51CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.