WordPress · Download Manager · CVE-2026-92714
**Name of the Vulnerable Software and Affected Versions**
Download Manager versions prior to 3.3.69
**Description**
An Insecure Direct Object Reference (IDOR) exists in the `duplicate()` function hooked on `admin init`. The issue occurs because the handler verifies only the generic `edit posts` capability and a static nonce (`NONCE KEY`) without performing object-level authorization checks against the targeted `wpdmpro` package ID. Authenticated attackers with Author-level access or higher can duplicate arbitrary packages owned by other users, including administrators. This process copies all package metadata, such as protected file references, role-based access restrictions, and password lock settings, into a clone owned by the attacker, who can then remove restrictions to access protected files.
**Recommendations**
Update to a version newer than 3.3.68.
As a temporary mitigation, restrict users with Author-level access from accessing the administrative functions related to the `duplicate()` function.