CVE-2025-12177

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.
Configurations

No configuration.

History

08 Nov 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-08 04:15

Updated : 2025-11-12 16:19


NVD link : CVE-2025-12177

Mitre link : CVE-2025-12177

CVE.ORG link : CVE-2025-12177


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key