CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 3.0.0
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions CM Download Manager allows Path Traversal. This issue affects CM Download Manager: from n/a through 2.9.6.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Apr 1, 2025
CVE-2025-30910 on NVD →
CM Download Manager <= 2.9.6 - Unauthenticated Arbitrary File Deletion
critical
The CM Download Manager – Simplify file sharing with powerful download management plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deletescreenshot() function in all versions up to, and including, 2.9.6. This makes it possible for unauthenticated attackers to...
- CVSS:
- 9.1
- Affected:
- up to 2.9.6
- Fixed in:
- 3.0.0
- Disclosed:
- Mar 27, 2025
CVE-2025-30910 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.9.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
- Disclosed:
- Mar 3, 2025
CVE-2025-24758 on NVD →
CM Download Manager < 2.9.1 - Cross-Site Request Forgery via editHeader
medium
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.1. This is due to missing or incorrect nonce validation on the 'editHeader' function. This makes it possible for unauthenticated attackers to edit downloads via a forged request granted they can trick a site a...
- CVSS:
- 4.3
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Mar 25, 2024
CVE-2024-1962 on NVD →
CM Download Manager < 2.9.0 - Cross-Site Request Forgery via delHeader
medium
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.0. This is due to missing or incorrect nonce validation on the 'delHeader' function. This makes it possible for unauthenticated attackers to delete downloads via a forged request granted they can trick a site...
- CVSS:
- 4.3
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Mar 25, 2024
CVE-2024-1232 on NVD →
CM Download Manager < 2.9.0 - Cross-Site Request Forgery via unpublishHeader
medium
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.0. This is due to missing or incorrect nonce validation on the 'unpublishHeader' function. This makes it possible for unauthenticated attackers to unpublish downloads via a forged request granted they can tric...
- CVSS:
- 4.3
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Mar 25, 2024
CVE-2024-1231 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.9.0
unknown
[en] The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Mar 25, 2024
CVE-2024-1231 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.9.0
unknown
[en] The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Mar 25, 2024
CVE-2024-1232 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.9.1
unknown
[en] The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Mar 25, 2024
CVE-2024-1962 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.8.6
unknown
[en] The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.6
- Disclosed:
- Sep 26, 2022
CVE-2022-3076 on NVD →
CM Download Manager <= 2.8.5 - Authenticated (Administrator+) Arbitrary File Upload
high
The CM Download Manager plugin for WordPress is vulnerable to arbitrary file uploads because it allows administrators to choose the php extension as an allowable file extension in versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 7.2
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.6
- Disclosed:
- Sep 5, 2022
CVE-2022-3076 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.8.0
unknown
[en] Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Jul 7, 2021
CVE-2020-24146 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.8.0
unknown
[en] Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Jul 7, 2021
CVE-2020-24145 on NVD →
CM Download Manager < 2.8.0 - Directory Traversal to Arbitrary File Deletion and Denial of Service
high
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
- CVSS:
- 8.1
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Apr 13, 2021
CVE-2020-24146 on NVD →
CM Download Manager <= 2.7.0 - Cross-Site Scripting
medium
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.0 via a crafted deletescreenshot action due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's bro...
- CVSS:
- 6.1
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Apr 13, 2021
CVE-2020-24145 on NVD →
CM Download Manager <= 2.7.0 - Authenticated Stored Cross-Site Scripting
medium
The CM Download Manager plugin for WordPress is vulnerable to Authenticated Stored Cross-Site Scripting via the ‘filename’ parameter in versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for highly privileged attackers to inject arbitrary web scripts...
- CVSS:
- 5.5
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Oct 22, 2020
CVE-2020-27344 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.8.0
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by qwebee in WordPress CM Download Manager plugin (versions <= 2.7.0).
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Oct 22, 2020
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.8.0
unknown
[en] The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Oct 21, 2020
CVE-2020-27344 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.0.7
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings p...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Dec 5, 2014
CVE-2014-9129 on NVD →
CM Download Manager – Simplify file sharing with powerful download management [cm-download-manager] < 2.0.4
unknown
[en] The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Dec 5, 2014
CVE-2014-8877 on NVD →
CM Download Manager <= 2.0.6 - Cross-Site Request Forgery to Cross-Site Scripting
medium
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page t...
- CVSS:
- 6.1
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Dec 1, 2014
CVE-2014-9129 on NVD →
CM Download Manager <= 2.0.3 - Code Injection
critical
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.
- CVSS:
- 9.8
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Nov 10, 2014
CVE-2014-8877 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database