CVE-2026-2419 | Lester Chan WP-DownloadManager Plugin up to 1.69 on WordPress download_path path traversal
A vulnerability classified as critical has been found in Lester Chan WP-DownloadManager Plugin up to 1.69 on WordPress. This affects an unknown function. This manipulation of the argument download_path causes path traversal.
This vulnerability is tracked as CVE-2026-2419. The attack is possible to be carried out remotely. No exploit exists.