
CVE-2026-2571 The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versi… https://www.cve.org/CVERecord?id=CVE-2026-2571
Post summary
A new CVE (2026‑2571) identifies a missing capability check in the Download Manager WordPress plugin, allowing unauthorized data access.

