Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit repo containing one primary script (Cve.py) and a minimal README. The script is a command-line exploit for the claimed CVE-2026-39676 affecting the WordPress Download Manager plugin up to version 3.3.52. Its purpose is to exploit a missing authorization / unauthenticated IDOR condition in plugin download/media handling so an unauthenticated user can access protected files. Repository structure is simple: Cve.py implements all logic, including banner output, argument parsing, HTTP session setup, target validation, AJAX endpoint verification, exploitation routines, and local file saving. README.md only briefly names the target and vulnerability class. Operationally, the exploit creates a requests session, disables TLS verification warnings, and builds the target AJAX endpoint at /wp-admin/admin-ajax.php. It first checks whether the target site is reachable, then verifies that the WordPress AJAX handler responds. The main exploitation routine shown in the content, exploit_protect_media_bypass, prepares crafted POST/GET parameter sets for vulnerable AJAX actions including wpdm_download_file and wpdm_frontend_download. The script also exposes higher-level workflow methods referenced in main(), including download_file() for targeting a specific package/file ID and run_full_scan() for broader scanning/enumeration behavior. Successful responses are treated as downloaded file data and can be written to an operator-specified output path. Overall, this is a real exploit script rather than a detector: it actively attempts unauthorized retrieval of protected content from a vulnerable WordPress plugin over web requests. It is not part of a larger exploitation framework, and its maturity is best described as OPERATIONAL because it contains working exploit logic and file retrieval capability, but not a highly modular or framework-driven payload system.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.