CVE-2025-3848 | Download Manager and Payment Form up to 2.7.13 on WordPress update authorization (EUVD-2025-19677)
A vulnerability has been found in Download Manager and Payment Form up to 2.7.13 on WordPress and classified as critical. Affected by this vulnerability is the function update. The manipulation leads to authorization bypass.
This vulnerability is known as CVE-2025-3848. The attack can be launched remotely. There is no exploit available.