CVE-2025-12177 | Download Manager Plugin up to 3.3.30 on WordPress Cron Trigger deleteExpired hard-coded key (EUVD-2025-38361)
A vulnerability identified as critical has been detected in Download Manager Plugin up to 3.3.30 on WordPress. This vulnerability affects the function deleteExpired of the component Cron Trigger Handler. This manipulation causes use of hard-coded cryptographic key
.
This vulnerability appears as CVE-2025-12177. The attack may be initiated remotely. There is no available exploit.