CVE-2026-4057Disclosure

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verifying post ownership via `current_user_can('edit_post', $id)`, and the destructive operations executing before the admin-level check in `mediaAccessControl()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to strip all protection metadata (password, access restrictions, private flag) from any media file they do not own, making admin-protected files publicly accessible via their direct URL.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-19: 1Technical Details · 2026-04-10: 204-1004-1104-19
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure1General1
2026-04-111
Disclosure1
2026-04-191
PoC1
Full discourse4 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4057-download-manager-version-3-3-51-medium-vulnerability-proof-of-concept CVE-2026-4057 #WordPress plugin #vulnerability download-manager #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post links to a proof‑of‑concept for CVE‑2026‑4057 affecting the WordPress Download Manager plugin, but provides no further technical details or evidence of active exploitation.

    0000049
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4057 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4057 #CVE-2026-4057 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/uZz0cNufxi

    Post summary

    The tweet announces a new CVE (CVE-2026-4057) affecting WordPress, stating its medium severity and linking to the NVD entry, but provides no exploit, patch, or detailed technical information.

    0000042
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4057 The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMedia… https://www.cve.org/CVERecord?id=CVE-2026-4057

    Post summary

    The text reports a missing capability check in the Download Manager plugin that allows unauthorized data modification, but it lacks evidence of PoC, exploit code, active exploitation, or a patch.

    00000120
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4057 Unauthorized Data Modification in WordPress Download Manager Plugin 3.3.5... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4057 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE‑2026‑4057, an unauthorized data modification flaw in WordPress Download Manager 3.3.5, and provides links to detailed information but offers no proof of concept, exploit, or patch details.

    0000049
    4.0K followersView on X

Explore more