CVE Vulnerabilities

CVE-2025-12177

Use of Hard-coded Cryptographic Key

Published: Nov 08, 2025 | Modified: Nov 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Potential Mitigations

References