The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14235 affects the Download Manager WordPress plugin versions before 3.3.62 and represents a critical flaw in how authentication tokens are handled. The vulnerability stems from improper implementation of temporary download tokens that lack session binding and fail to expire promptly. This transforms what should be a short-lived, single-use credential into a long-lived, multi-use bearer token. Any attacker who obtains a leaked download key can repeatedly access role- or password-protected package files without proper authorization, effectively bypassing WordPress's access control mechanisms. This vulnerability affects website administrators running affected plugin versions and content creators who rely on the plugin to protect sensitive downloads from unauthorized distribution.
While CVE-2026-14235 does not map to specific MITRE ATT&CK techniques in the current taxonomy, Casky.ai's 754 security skills powered by Claude AI with extended reasoning would detect attack patterns consistent with CWE-284 (Improper Access Control) and credential-based lateral movement. A practitioner reviewing findings would observe indicators such as: repeated download requests using identical tokens across different sessions, tokens accessed from geographically disparate IP addresses, download activity from accounts without appropriate role permissions, and lack of token expiration events in access logs. Casky's skill-based detection would highlight anomalous patterns in authentication flows, token lifecycle management violations, and unauthorized resource access attempts—enabling security teams to identify compromised download tokens and malicious actors exploiting this design flaw before sensitive content is widely distributed.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14235. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation