CVE-2026-4057 | codename065 Download Manager Plugin up to 3.3.51 on WordPress makeMediaPublic ID authorization
A vulnerability, which was classified as critical, was found in codename065 Download Manager Plugin up to 3.3.51 on WordPress. Affected by this vulnerability is the function makeMediaPublic. Such manipulation of the argument ID leads to missing authorization.
This vulnerability is listed as CVE-2026-4057. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.