Download Panel WordPress Plugin Missing Authorization Vulnerability Allows Arbitrary Settings Modification

Vulnerability

A vulnerability exists in the Download Panel plugin for WordPress, in all versions through 1.3.3, allowing unauthorized modification of plugin settings. This issue arises from a missing capability check on the 'wp_ajax_save_settings' AJAX action, which enables authenticated attackers with Subscriber-level access and above to arbitrarily change settings such as display text, download links, button colors, and other visual customizations.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, allowing attackers to modify visual elements and functionality associated with the Download Panel plugin.

Added: Nov 18, 2025, 9:28 AM
Updated: Nov 18, 2025, 3:09 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
0.0
relevance
1.1
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.