plugin

Download Manager Vulnerabilities

184 known security issues reported for the Download Manager WordPress plugin. Most recent disclosed Aug 5, 2026.

2 critical 19 high 63 medium

Running Download Manager on your site? Check whether your installed version is affected.

Scan your site free

Download Manager < 3.3.66 - Unauthenticated Stored Cross-Site Scripting

high

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected...

CVSS:
7.2
Affected:
up to 3.3.66
Fixed in:
3.3.66
Disclosed:
Aug 5, 2026

CVE-2026-14292 on NVD →

Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to i...

CVSS:
6.4
Affected:
up to 3.3.66
Fixed in:
3.3.67
Disclosed:
Jul 31, 2026

CVE-2026-16685 on NVD →

Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...

CVSS:
6.4
Affected:
up to 3.3.61
Fixed in:
3.3.62
Disclosed:
Jul 8, 2026

CVE-2026-14343 on NVD →

Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...

CVSS:
6.4
Affected:
up to 3.3.60
Fixed in:
3.3.61
Disclosed:
Jun 30, 2026

CVE-2026-13733 on NVD →

Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verify...

CVSS:
4.3
Affected:
up to 3.3.51
Fixed in:
3.3.52
Disclosed:
Apr 9, 2026

CVE-2026-4057 on NVD →

Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is e...

CVSS:
6.4
Affected:
up to 3.3.52
Fixed in:
3.3.53
Disclosed:
Apr 8, 2026

CVE-2026-5357 on NVD →

Download Manager - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter vulnerability

medium

Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter vulnerability

CVSS:
4.3
Affected:
up to 3.3.49
Fixed in:
3.3.50
Disclosed:
Mar 19, 2026

Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive info...

CVSS:
4.3
Affected:
up to 3.3.49
Fixed in:
3.3.50
Disclosed:
Mar 18, 2026

CVE-2026-2571 on NVD →

Download Manager <= 3.3.52 - Missing Authorization

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.3.52. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.3.52
Fixed in:
3.3.53
Disclosed:
Feb 19, 2026

CVE-2026-39676 on NVD →

Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter

medium

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possibl...

CVSS:
6.1
Affected:
up to 3.3.46
Fixed in:
3.3.47
Disclosed:
Feb 17, 2026

CVE-2026-1666 on NVD →

Download Manager <= 3.3.53 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 3.3.53
Fixed in:
3.3.54
Disclosed:
Feb 10, 2026

CVE-2026-39615 on NVD →

Download Manager [download-manager] < 3.3.41

unknown

[en] The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers...

Affected:
up to 3.3.41
Fixed in:
3.3.41
Disclosed:
Jan 6, 2026

CVE-2025-15364 on NVD →

Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword

high

The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to ch...

CVSS:
7.3
Affected:
up to 3.3.40
Fixed in:
3.3.41
Disclosed:
Jan 5, 2026

CVE-2025-15364 on NVD →

Download Manager [download-manager] < 3.3.33

unknown

[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscribe...

Affected:
up to 3.3.33
Fixed in:
3.3.33
Disclosed:
Dec 18, 2025

CVE-2025-13498 on NVD →

Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-lev...

CVSS:
4.3
Affected:
up to 3.3.32
Fixed in:
3.3.33
Disclosed:
Dec 17, 2025

CVE-2025-13498 on NVD →

Download Manager [download-manager] <= 3.3.32 (unfixed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32.

Affected:
up to 3.3.32
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63070 on NVD →

Download Manager [download-manager] < 3.3.31

unknown

[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletio...

Affected:
up to 3.3.31
Fixed in:
3.3.31
Disclosed:
Nov 8, 2025

CVE-2025-12177 on NVD →

Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of...

CVSS:
5.3
Affected:
up to 3.3.30
Fixed in:
3.3.31
Disclosed:
Nov 7, 2025

CVE-2025-12177 on NVD →

Download Manager <= 3.3.32 - Authenticated (Subscriber+) Information Exposure

medium

The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 3.3.32
Fixed in:
3.3.33
Disclosed:
Sep 30, 2025

CVE-2025-63070 on NVD →

Download Manager <= 3.3.25 - Unauthenticated Sensitive Information Exposure

medium

The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.3.25
Fixed in:
3.3.26
Disclosed:
Sep 26, 2025

CVE-2025-60092 on NVD →

Download Manager <= 3.3.24 - Cross-Site Request Forgery

medium

The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...

CVSS:
4.3
Affected:
up to 3.3.24
Fixed in:
3.3.25
Disclosed:
Sep 26, 2025

CVE-2025-60093 on NVD →

Download Manager [download-manager] < 3.3.25

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager allows Cross Site Request Forgery. This issue affects Download Manager: from n/a through 3.3.24.

Affected:
up to 3.3.25
Fixed in:
3.3.25
Disclosed:
Sep 26, 2025

CVE-2025-60093 on NVD →

Download Manager [download-manager] <= 3.3.25 (unfixed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.24.

Affected:
up to 3.3.25
Fix:
No patched version reported
Disclosed:
Sep 26, 2025

CVE-2025-60092 on NVD →

Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter

medium

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 3.3.23
Fixed in:
3.3.24
Disclosed:
Sep 18, 2025

CVE-2025-10146 on NVD →

Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 3.3.18
Fixed in:
3.3.19
Disclosed:
Jun 18, 2025

CVE-2025-4367 on NVD →

Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion

high

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the s...

CVSS:
8.8
Affected:
up to 3.3.12
Fixed in:
3.3.13
Disclosed:
Apr 18, 2025

CVE-2025-3404 on NVD →

Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary...

CVSS:
5.4
Affected:
up to 3.3.12
Fixed in:
3.3.13
Disclosed:
Apr 17, 2025

CVE-2025-3056 on NVD →

Download Manager [download-manager] < 3.3.07

unknown

[en] The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

Affected:
up to 3.3.07
Fixed in:
3.3.07
Disclosed:
Mar 16, 2025

CVE-2024-13126 on NVD →

Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite

medium

The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory,...

CVSS:
5.4
Affected:
up to 3.3.08
Fixed in:
3.3.09
Disclosed:
Mar 12, 2025

CVE-2025-1785 on NVD →

Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory

medium

The Download Manager plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 3.3.06. This is due to plugin not providing any access restrictions to the direct in which download files are uploaded. This makes it possible for unauthenticated attackers to access downloads that sh...

CVSS:
5.3
Affected:
up to 3.3.06
Fixed in:
3.3.07
Disclosed:
Jan 17, 2025

CVE-2024-13126 on NVD →

Download Manager [download-manager] < 3.3.04

unknown

[en] Missing Authorization vulnerability in W3 Eden, Inc. Download Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through 3.3.03.

Affected:
up to 3.3.04
Fixed in:
3.3.04
Disclosed:
Dec 31, 2024

CVE-2024-56217 on NVD →

Download Manager [download-manager] < 3.3.03

unknown

[en] The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.3.03
Fixed in:
3.3.03
Disclosed:
Dec 20, 2024

CVE-2024-10706 on NVD →

Download Manager <= 3.3.03 - Missing Authorization

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.03. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.3.03
Fixed in:
3.3.04
Disclosed:
Dec 19, 2024

CVE-2024-56217 on NVD →

Download Manager [download-manager] < 3.3.04

unknown

[en] The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated...

Affected:
up to 3.3.04
Fixed in:
3.3.04
Disclosed:
Dec 19, 2024

CVE-2024-11740 on NVD →

Download Manager [download-manager] < 3.3.04

unknown

[en] The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected file...

Affected:
up to 3.3.04
Fixed in:
3.3.04
Disclosed:
Dec 19, 2024

CVE-2024-11768 on NVD →

Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution

high

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attac...

CVSS:
7.3
Affected:
up to 3.3.03
Fixed in:
3.3.04
Disclosed:
Dec 18, 2024

CVE-2024-11740 on NVD →

Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.

CVSS:
5.3
Affected:
up to 3.3.03
Fixed in:
3.3.04
Disclosed:
Dec 18, 2024

CVE-2024-11768 on NVD →

Download Manager <= 3.3.02 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.02 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 3.3.02
Fixed in:
3.3.03
Disclosed:
Nov 29, 2024

CVE-2024-10706 on NVD →

Download Manager [download-manager] < 3.3.00

unknown

[en] The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.

Affected:
up to 3.3.00
Fixed in:
3.3.00
Disclosed:
Oct 30, 2024

CVE-2024-8444 on NVD →

Download Manager <= 3.2.99 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_login_form' shortcode in all versions up to, and including, 3.2.99 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...

CVSS:
6.4
Affected:
up to 3.2.99
Fixed in:
3.3.00
Disclosed:
Oct 9, 2024

CVE-2024-8444 on NVD →

Download Manager <= 3.2.98 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.98 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 3.2.98
Fixed in:
3.2.99
Disclosed:
Sep 23, 2024

CVE-2024-8284 on NVD →

Download Manager [download-manager] < 3.2.98

unknown

[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers,...

Affected:
up to 3.2.98
Fixed in:
3.2.98
Disclosed:
Jul 31, 2024

CVE-2024-6208 on NVD →

Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 3.2.97
Fixed in:
3.2.98
Disclosed:
Jul 30, 2024

CVE-2024-6208 on NVD →

Download Manager [download-manager] < 3.2.90

unknown

[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.

Affected:
up to 3.2.90
Fixed in:
3.2.90
Disclosed:
Jun 13, 2024

CVE-2024-2098 on NVD →

Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary

high

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.

CVSS:
7.5
Affected:
up to 3.2.89
Fixed in:
3.2.90
Disclosed:
Jun 12, 2024

CVE-2024-2098 on NVD →

Download Manager [download-manager] < 3.2.94

unknown

[en] The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attri...

Affected:
up to 3.2.94
Fixed in:
3.2.94
Disclosed:
Jun 12, 2024

CVE-2024-5266 on NVD →

Download Manager [download-manager] < 3.2.87

unknown

[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to in...

Affected:
up to 3.2.87
Fixed in:
3.2.87
Disclosed:
Jun 12, 2024

CVE-2024-1766 on NVD →

Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes

medium

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes...

CVSS:
6.4
Affected:
up to 3.2.92
Fixed in:
3.2.94
Disclosed:
Jun 11, 2024

CVE-2024-5266 on NVD →

Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject...

CVSS:
4.4
Affected:
up to 3.2.86
Fixed in:
3.2.87
Disclosed:
Jun 11, 2024

CVE-2024-1766 on NVD →

Download Manager [download-manager] < 3.2.94

unknown

[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

Affected:
up to 3.2.94
Fixed in:
3.2.94
Disclosed:
Jun 5, 2024

CVE-2024-4001 on NVD →

Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...

CVSS:
6.4
Affected:
up to 3.2.93
Fixed in:
3.2.94
Disclosed:
Jun 4, 2024

CVE-2024-4001 on NVD →

Download Manager [download-manager] < 3.2.91

unknown

[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...

Affected:
up to 3.2.91
Fixed in:
3.2.91
Disclosed:
May 31, 2024

CVE-2024-4160 on NVD →

Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 3.2.90
Fixed in:
3.2.91
Disclosed:
May 30, 2024

CVE-2024-4160 on NVD →

Download Manager [download-manager] < 3.2.83

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.

Affected:
up to 3.2.83
Fixed in:
3.2.83
Disclosed:
May 17, 2024

CVE-2024-32131 on NVD →

Download Manager [download-manager] < 3.2.85

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.

Affected:
up to 3.2.85
Fixed in:
3.2.85
Disclosed:
Mar 19, 2024

CVE-2024-29114 on NVD →

Download Manager <= 3.2.84 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 3.2.84
Fixed in:
3.2.85
Disclosed:
Mar 16, 2024

CVE-2024-29114 on NVD →

Download Manager [download-manager] < 3.2.85

unknown

[en] The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).

Affected:
up to 3.2.85
Fixed in:
3.2.85
Disclosed:
Mar 13, 2024

CVE-2023-6785 on NVD →

Download Manager [download-manager] < 3.2.86

unknown

[en] The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contr...

Affected:
up to 3.2.86
Fixed in:
3.2.86
Disclosed:
Mar 13, 2024

CVE-2023-6954 on NVD →

Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributo...

CVSS:
6.4
Affected:
up to 3.2.85
Fixed in:
3.2.86
Disclosed:
Feb 28, 2024

CVE-2023-6954 on NVD →

Download Manager <= 3.2.84 - Missing Authorization

medium

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).

CVSS:
5.3
Affected:
up to 3.2.84
Fixed in:
3.2.85
Disclosed:
Feb 28, 2024

CVE-2023-6785 on NVD →

Download Manager [download-manager] < 3.2.83

unknown

[en] The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

Affected:
up to 3.2.83
Fixed in:
3.2.83
Disclosed:
Jan 1, 2024

CVE-2023-6421 on NVD →

Download Manager <= 3.2.82 - Unauthenticated Password Leak

medium

The Download Manager plugin for WordPress is vulnerable to information Exposure in all versions up to, and including, 3.2.82. This is due to the plugin leaking the password to a protected file when it receives an invalid password. This makes it possible for unauthenticated attackers to gain access to protected files.

CVSS:
5.3
Affected:
up to 3.2.82
Fixed in:
3.2.83
Disclosed:
Nov 29, 2023

CVE-2023-6421 on NVD →

Download Manager [download-manager] < 3.2.71

unknown

[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

Affected:
up to 3.2.71
Fixed in:
3.2.71
Disclosed:
Jun 9, 2023

CVE-2023-2305 on NVD →

Download Manager [download-manager] < 3.2.71

unknown

[en] The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowled...

Affected:
up to 3.2.71
Fixed in:
3.2.71
Disclosed:
May 30, 2023

CVE-2023-1524 on NVD →

Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 3.2.70
Fixed in:
3.2.71
Disclosed:
May 12, 2023

CVE-2023-2305 on NVD →

Download Manager <= 3.2.70 - Insufficient Authorization to Information Disclosure

medium

The Download Manager plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.2.7.0, due to insufficient validation of passwords on password protected files. This makes it possible for authenticated attackers, with access to the downloads area to create a password protected post...

CVSS:
4.3
Affected:
up to 3.2.70
Fixed in:
3.2.71
Disclosed:
May 8, 2023

CVE-2023-1524 on NVD →

Download Manager [download-manager] < 3.2.60

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

Affected:
up to 3.2.60
Fixed in:
3.2.60
Disclosed:
Apr 18, 2023

CVE-2022-45836 on NVD →

Download Manager Pro <= 6.2.9 - Unauthenticated Information Disclosure

medium

The Download Manager Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.2.9 due to the plugin leaking the master key. This can allow unauthenticated attackers to retrieve the key and extract sensitive data contained in password protected package files.

CVSS:
5.3
Affected:
4.0 – 6.3.0
Fixed in:
6.3.0
Disclosed:
Apr 10, 2023

CVE-2023-1809 on NVD →

Download Manager [download-manager] < 3.2.62

unknown

[en] The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

Affected:
up to 3.2.62
Fixed in:
3.2.62
Disclosed:
Jan 16, 2023

CVE-2022-4476 on NVD →

Download Manager <= 3.2.61 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 3.2.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 3.2.61
Fixed in:
3.2.62
Disclosed:
Dec 20, 2022

CVE-2022-4476 on NVD →

Download Manager <= 3.2.59 - Refleced Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘packages-shortcode-toolbar.php’, 'Shortcodes.php', and 'category-shortcode-toolbar.php' (in both 'src/Package/views/' and 'src/Category/views/') files in versions up to, and including, 3.2.59 due to insufficient input san...

CVSS:
6.1
Affected:
up to 3.2.59
Fixed in:
3.2.60
Disclosed:
Nov 29, 2022

CVE-2022-45836 on NVD →

Download Manager [download-manager] < 3.2.55

unknown

[en] The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

Affected:
up to 3.2.55
Fixed in:
3.2.55
Disclosed:
Sep 26, 2022

CVE-2022-2926 on NVD →

Download Manager [download-manager] < 3.2.71

unknown

[en] The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserial...

Affected:
up to 3.2.71
Fixed in:
3.2.71
Disclosed:
Sep 6, 2022

CVE-2022-2436 on NVD →

Download Manager [download-manager] < 3.2.51

unknown

[en] The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it po...

Affected:
up to 3.2.51
Fixed in:
3.2.51
Disclosed:
Sep 6, 2022

CVE-2022-2431 on NVD →

Download Manager <= 3.2.54 - Authenticated (Admin+) Path Traversal

medium

The Download Manager plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.2.54 via the File Browser Root field. This makes it possible for administrator-level attackers to list and read arbitrary files and folders outside of the blog directory.

CVSS:
4.9
Affected:
up to 3.2.55
Fixed in:
3.2.55
Disclosed:
Sep 5, 2022

CVE-2022-2926 on NVD →

Download Manager [download-manager] < 3.2.49

unknown

[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Affected:
up to 3.2.49
Fixed in:
3.2.49
Disclosed:
Aug 23, 2022

CVE-2022-36288 on NVD →

Download Manager [download-manager] < 3.2.49

unknown

[en] Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Affected:
up to 3.2.49
Fixed in:
3.2.49
Disclosed:
Aug 23, 2022

CVE-2022-34658 on NVD →

Download Manager [download-manager] < 3.2.49

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Affected:
up to 3.2.49
Fixed in:
3.2.49
Disclosed:
Aug 22, 2022

CVE-2022-34347 on NVD →

Download Manager [download-manager] < 3.2.50

unknown

[en] The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.

Affected:
up to 3.2.50
Fixed in:
3.2.50
Disclosed:
Aug 22, 2022

CVE-2022-2362 on NVD →

Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization

high

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize t...

CVSS:
8.8
Affected:
up to 3.2.49
Fixed in:
3.2.50
Disclosed:
Aug 17, 2022

CVE-2022-2436 on NVD →

Download Manager <= 3.2.53 - Reflected Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 3.2.53
Fixed in:
3.2.54
Disclosed:
Aug 4, 2022

Download Manager [download-manager] < 3.2.54

unknown

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 3.2.54
Fixed in:
3.2.54
Disclosed:
Aug 4, 2022

Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings Update

high

The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation on the updateTemplateStatus function. This makes it possible for unauthenticated attackers to trigger setting changes forged request grante...

CVSS:
8.8
Affected:
up to 3.2.48
Fixed in:
3.2.49
Disclosed:
Aug 2, 2022

CVE-2022-34347 on NVD →

Download Manager <= 3.2.48 - Cross-Site Request Forgery

high

The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete stats and clear the plugin's cache via forged request granted they can tric...

CVSS:
8.8
Affected:
up to 3.2.48
Fixed in:
3.2.49
Disclosed:
Aug 2, 2022

CVE-2022-36288 on NVD →

Download Manager <= 3.2.49 - IP Blocking Bypass

medium

The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 due to the way the visitor's IP address is determined. This allows an unauthenticated attacker to spoof their IP address to obtain access to files that are protected by this functionality.

CVSS:
5.3
Affected:
up to 3.2.49
Fixed in:
3.2.50
Disclosed:
Aug 1, 2022

CVE-2022-2362 on NVD →

Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion

high

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possibl...

CVSS:
8.8
Affected:
up to 3.2.50
Fixed in:
3.2.51
Disclosed:
Jul 27, 2022

CVE-2022-2431 on NVD →

Download Manager [download-manager] < 3.2.47

unknown

[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and abo...

Affected:
up to 3.2.47
Fixed in:
3.2.47
Disclosed:
Jul 18, 2022

CVE-2022-2101 on NVD →

Download Manager [download-manager] < 3.2.44

unknown

[en] The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

Affected:
up to 3.2.44
Fixed in:
3.2.44
Disclosed:
Jul 17, 2022

CVE-2022-2168 on NVD →

Download Manager <= 3.2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ and 'label' parameters in versions up to, and including, 3.2.48 due to insufficient input sanitization and output escaping when setting lock options for downloadables. This makes it possible for authenticated attacke...

CVSS:
5.4
Affected:
up to 3.2.48
Fixed in:
3.2.49
Disclosed:
Jul 6, 2022

CVE-2022-34658 on NVD →

Download Manager <= 3.2.43 - Reflected Cross-Site Scripting

medium

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 3.2.43
Fixed in:
3.2.44
Disclosed:
Jun 27, 2022

CVE-2022-2168 on NVD →

Download Manager [download-manager] < 3.2.44

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Download Manager plugin (versions <= 3.2.43). Update the WordPress Download Manager plugin to the latest available version (at least 3.2.44).

Affected:
up to 3.2.44
Fixed in:
3.2.44
Disclosed:
Jun 27, 2022

Download Manager <= 3.2.43 - Reflected Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 3.2.43
Fixed in:
3.2.44
Disclosed:
Jun 23, 2022

Download Manager [download-manager] < 3.2.44

unknown

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...

Affected:
up to 3.2.44
Fixed in:
3.2.44
Disclosed:
Jun 23, 2022

Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to...

CVSS:
6.4
Affected:
up to 3.2.46
Fixed in:
3.2.47
Disclosed:
Jun 21, 2022

CVE-2022-2101 on NVD →

Download Manager [download-manager] < 3.2.43

unknown

[en] The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.

Affected:
up to 3.2.43
Fixed in:
3.2.43
Disclosed:
Jun 13, 2022

CVE-2022-1985 on NVD →

Download Manager <= 3.2.42 - Reflected Cross-Site Scripting

medium

The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.

CVSS:
6.1
Affected:
up to 3.2.42
Fixed in:
3.2.43
Disclosed:
Jun 2, 2022

CVE-2022-1985 on NVD →

Download Manager [download-manager] < 3.2.39

unknown

[en] The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

Affected:
up to 3.2.39
Fixed in:
3.2.39
Disclosed:
Apr 11, 2022

CVE-2022-0828 on NVD →

Download Manager <= 3.2.38 - Unauthenticated Brute Force of File Master Key

high

The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

CVSS:
7.5
Affected:
up to 3.2.39
Fixed in:
3.2.39
Disclosed:
Mar 16, 2022

CVE-2022-0828 on NVD →

Download Manager [download-manager] < 3.2.25

unknown

[en] The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

Affected:
up to 3.2.25
Fixed in:
3.2.25
Disclosed:
Mar 7, 2022

CVE-2021-25087 on NVD →

Download Manager [download-manager] < 3.2.34

unknown

[en] The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

Affected:
up to 3.2.34
Fixed in:
3.2.34
Disclosed:
Feb 21, 2022

CVE-2021-25069 on NVD →

Download Manager <= 3.2.34 - Sensitive Information Disclosure

high

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

CVSS:
7.5
Affected:
up to 3.2.35
Fixed in:
3.2.35
Disclosed:
Feb 2, 2022

CVE-2021-25087 on NVD →

WordPress Download Manager <= 3.2.33 - Authenticated SQL Injection

high

The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

CVSS:
8.8
Affected:
up to 3.2.34
Fixed in:
3.2.34
Disclosed:
Jan 20, 2022

CVE-2021-25069 on NVD →

Download Manager [download-manager] < 3.2.22

unknown

[en] The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber i...

Affected:
up to 3.2.22
Fixed in:
3.2.22
Disclosed:
Dec 27, 2021

CVE-2021-24969 on NVD →

WordPress Download Manager <= 3.2.21 - Cross-Site Scripting

medium

The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is abl...

CVSS:
6.4
Affected:
up to 3.2.22
Fixed in:
3.2.22
Disclosed:
Nov 29, 2021

CVE-2021-24969 on NVD →

Download Manager [download-manager] < 3.2.16

unknown

[en] The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

Affected:
up to 3.2.16
Fixed in:
3.2.16
Disclosed:
Nov 1, 2021

CVE-2021-24773 on NVD →

WordPress Download Manager <= 3.2.15 - Cross-Site Scripting

medium

The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 3.2.16
Fixed in:
3.2.16
Disclosed:
Sep 29, 2021

CVE-2021-24773 on NVD →

WordPress Download Manager <= 3.2.12 - Cross-Site Request Forgery

high

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for unauthenticated attackers to save the plugins email settings via a forged r...

CVSS:
7.1
Affected:
up to 3.2.13
Fixed in:
3.2.13
Disclosed:
Aug 9, 2021

Download Manager [download-manager] < 3.2.13

unknown

Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Download Manager plugin (versions <= 3.2.12).

Affected:
up to 3.2.13
Fixed in:
3.2.13
Disclosed:
Aug 9, 2021

Download Manager [download-manager] < 3.2.13

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for unauthenticated attackers to save the plugins email settings via a forged r...

Affected:
up to 3.2.13
Fixed in:
3.2.13
Disclosed:
Aug 9, 2021

Download Manager [download-manager] < 3.1.25

unknown

[en] Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploade...

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Aug 5, 2021

CVE-2021-34638 on NVD →

Download Manager [download-manager] < 3.1.25

unknown

[en] Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Aug 5, 2021

CVE-2021-34639 on NVD →

WordPress Download Manager <= 3.1.24 - Authenticated File Upload

high

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.

CVSS:
7.5
Affected:
up to 3.1.24
Fixed in:
3.1.25
Disclosed:
Jul 29, 2021

CVE-2021-34639 on NVD →

WordPress Download Manager <= 3.1.24 - Cross-Site Scripting

medium

Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded Jav...

CVSS:
6.5
Affected:
up to 3.1.24
Fixed in:
3.1.25
Disclosed:
Jul 29, 2021

CVE-2021-34638 on NVD →

WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery

high

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a...

CVSS:
8.8
Affected:
up to 3.1.22
Fixed in:
3.1.22
Disclosed:
Apr 30, 2021

WordPress Download Manager < 3.1.19 - Arbitrary File Upload

high

The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level pr...

CVSS:
8.8
Affected:
up to 3.1.19
Fixed in:
3.1.19
Disclosed:
Apr 30, 2021

WordPress Download Manager < 3.1.23 - Arbitrary Asset Manager Usage

medium

The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers with low level privileges to reveal the nonce in pages available to them a...

CVSS:
6.3
Affected:
up to 3.1.23
Fixed in:
3.1.23
Disclosed:
Apr 30, 2021

Download Manager [download-manager] < 3.1.22

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a...

Affected:
up to 3.1.22
Fixed in:
3.1.22
Disclosed:
Apr 30, 2021

Download Manager [download-manager] < 3.1.23

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers with low level privileges to reveal the nonce in pages available to them a...

Affected:
up to 3.1.23
Fixed in:
3.1.23
Disclosed:
Apr 30, 2021

Download Manager [download-manager] < 3.1.19

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level pr...

Affected:
up to 3.1.19
Fixed in:
3.1.19
Disclosed:
Apr 30, 2021

Download Manager <= 3.1.17 - Missing Authorization

medium

The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable si...

CVSS:
5.3
Affected:
up to 3.1.18
Fixed in:
3.1.18
Disclosed:
Apr 16, 2021

Download Manager [download-manager] < 3.1.17

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable si...

Affected:
up to 3.1.17
Fixed in:
3.1.17
Disclosed:
Apr 16, 2021

Download Manager [download-manager] < 2.9.94

unknown

[en] The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

Affected:
up to 2.9.94
Fixed in:
2.9.94
Disclosed:
Sep 3, 2019

CVE-2019-15889 on NVD →

WordPress Download Manager <= 2.9.96 - Cross-Site Scripting

medium

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.9.97
Fixed in:
2.9.97
Disclosed:
Jun 16, 2019

Download Manager [download-manager] < 2.9.97

unknown

Multiple vulnerabilities found in WordPress Download Manager plugin (versions <= 2.9.96).

Affected:
up to 2.9.97
Fixed in:
2.9.97
Disclosed:
Jun 16, 2019

Download Manager [download-manager] < 2.9.97

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.9.97
Fixed in:
2.9.97
Disclosed:
Jun 16, 2019

Download Manager [download-manager] < 2.9.94

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by MgThuraMoeMyint on WordPress Download Manager plugin (versions <= 2.9.93).

Affected:
up to 2.9.94
Fixed in:
2.9.94
Disclosed:
Apr 23, 2019

WordPress Download Manager <= 2.9.93 - Cross-Site Scripting

medium

The WordPress Download Manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

CVSS:
6.1
Affected:
up to 2.9.94
Fixed in:
2.9.94
Disclosed:
Apr 13, 2019

CVE-2019-15889 on NVD →

Download Manager [download-manager] < 2.9.52

unknown

[en] The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.

Affected:
up to 2.9.52
Fixed in:
2.9.52
Disclosed:
Jan 16, 2018

CVE-2017-18032 on NVD →

Download Manager [download-manager] < 2.9.61

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Panagiotis Vagenas in WordPress Download Manager plugin (versions <=2.9.60).

Affected:
up to 2.9.61
Fixed in:
2.9.61
Disclosed:
Jan 10, 2018

WordPress Download Manager <= 2.9.6 - Cross-Site Request Forgery

medium

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for unauthenticated attackers to install malicious plugins and/or packa...

CVSS:
6.3
Affected:
up to 2.9.6
Fixed in:
2.9.61
Disclosed:
Jan 9, 2018

Download Manager [download-manager] < 2.9.61

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for unauthenticated attackers to install malicious plugins and/or packa...

Affected:
up to 2.9.61
Fixed in:
2.9.61
Disclosed:
Jan 9, 2018

Download Manager [download-manager] < 2.7.3

unknown

[en] The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Aug 7, 2017

CVE-2014-9260 on NVD →

WordPress Download Manager < 2.9.51 - Open Redirect

medium

Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS:
6.1
Affected:
up to 2.9.51
Fixed in:
2.9.51
Disclosed:
Jul 13, 2017

CVE-2017-2217 on NVD →

Download Manager [download-manager] < 2.9.50

unknown

[en] Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 2.9.50
Fixed in:
2.9.50
Disclosed:
Jul 7, 2017

CVE-2017-2216 on NVD →

Download Manager [download-manager] < 2.9.51

unknown

[en] Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Affected:
up to 2.9.51
Fixed in:
2.9.51
Disclosed:
Jul 7, 2017

CVE-2017-2217 on NVD →

Download Manager [download-manager] < 2.9.46

unknown

Authenticated Arbitrary File Upload Vulnerability exsists in WordPress WordPress Download Manager plugin <= 2.8.97 . It doesn't check what type of files you can upload so an attacker can upload .PHP files. Update the plugin.

Affected:
up to 2.9.46
Fixed in:
2.9.46
Disclosed:
Jun 27, 2017

WordPress Download Manager <= 2.9.51 - Cross-Site Scripting

medium

The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.

CVSS:
6.1
Affected:
up to 2.9.51
Fixed in:
2.9.52
Disclosed:
Jun 16, 2017

CVE-2017-18032 on NVD →

WordPress Download Manager <= 2.9.49 - Reflected Cross-Site Scripting

medium

The WordPress Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in versions up to, and including, 2.9.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 2.9.50
Fixed in:
2.9.50
Disclosed:
Jun 13, 2017

CVE-2017-2216 on NVD →

WordPress Download Manager <= 2.9.45 - Cross-Site Request Forgery

high

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it possible for unauthenticated attackers to modify administrative settings via a f...

CVSS:
8.8
Affected:
up to 2.9.45
Fixed in:
2.9.46
Disclosed:
Mar 1, 2017

Download Manager [download-manager] < 2.9.46

unknown

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it possible for unauthenticated attackers to modify administrative settings via a f...

Affected:
up to 2.9.46
Fixed in:
2.9.46
Disclosed:
Mar 1, 2017

Download Manager <= 2.8.7 - Missing Authorization

critical

The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary files with posts and subsequently download those files caus...

CVSS:
9.1
Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Jan 19, 2016

Download Manager <= 2.8.7 - Privilege Escalation

medium

The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.

CVSS:
6.5
Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Jan 19, 2016

Download Manager <= 2.8.7 - Sensitive Information Disclosure via Directory Listing

medium

The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers to read all of the files listed in that directory.

CVSS:
5.3
Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Jan 19, 2016

Download Manager [download-manager] < 2.8.8

unknown

This plugin is prone to privilege escalation, unauthenticated directory listings and unauthenticated post updating vulnerabilities. Update the plugin.

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Jan 19, 2016

Download Manager [download-manager] < 2.8.8

unknown

The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers to read all of the files listed in that directory.

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Jan 19, 2016

Download Manager [download-manager] < 2.8.8

unknown

The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Jan 19, 2016

Download Manager [download-manager] < 2.8.8

unknown

The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary files with posts and subsequently download those files caus...

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Jan 19, 2016

Download Manager [download-manager] < 2.7.95

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.7.95
Fixed in:
2.7.95
Disclosed:
Dec 20, 2015

WordPress Download Manager <= 2.7.94 - Stored Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 2.7.94
Fixed in:
2.7.95
Disclosed:
Jul 16, 2015

Download Manager [download-manager] < 2.7.95

unknown

Download Manager Free and Pro is prone to an authenticated stored XSS that allows an attacker to create new download package and upload files, called <svg onload=alert(0)>.jpg. This vulnerability works, when user try to edit this download package. Upgrade to the latest version.

Affected:
up to 2.7.95
Fixed in:
2.7.95
Disclosed:
Jul 16, 2015

Download Manager [download-manager] < 2.7.95

unknown

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages t...

Affected:
up to 2.7.95
Fixed in:
2.7.95
Disclosed:
Jul 16, 2015

Download Manager [download-manager] < 2.2.3

unknown

This plugin is prone to admin.php cid parameter cross site scripting vulnerability. Update the plugin.

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
May 15, 2015

WordPress Download Manager <= 2.7.4 - Remote Code Execution

critical

The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Dec 15, 2014

Download Manager [download-manager] >= 2.7.0 - <= 2.7.4

unknown

Download Manager plugin is prone to a remote code execution vulnerability via "/download-manager/wpdm-core.php". It allows attackers to execute arbitrary PHP code. Upgrade the plugin.

Affected:
2.7.0 – 2.7.4
Fixed in:
2.7.4
Disclosed:
Dec 15, 2014

Download Manager [download-manager] < 2.7.5

unknown

The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.

Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Dec 15, 2014

WordPress Download Manager <= 2.7.2 - Authenticated Arbitrary Options Update

high

The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.

CVSS:
8.1
Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Nov 24, 2014

CVE-2014-9260 on NVD →

Download Manager [download-manager] < 2.7

unknown

[en] Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.

Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Nov 4, 2014

CVE-2014-8585 on NVD →

Download Manager <= 2.2.2 - Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's brow...

CVSS:
6.1
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Aug 1, 2014

Download Manager [download-manager] < 2.2.3

unknown

The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's brow...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Aug 1, 2014

Download Manager [download-manager] < 2.5.9

unknown

[en] Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.

Affected:
up to 2.5.9
Fixed in:
2.5.9
Disclosed:
Feb 6, 2014

CVE-2013-7319 on NVD →

Download Manager < 2.5.9 - Stored Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.

CVSS:
7.2
Affected:
up to 2.5.8
Fixed in:
2.5.9
Disclosed:
Dec 8, 2013

CVE-2013-7319 on NVD →

Download Manager <= 2.5.8 - Cross-Site Scripting

medium

The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.3
Affected:
up to 2.5.8
Fixed in:
2.5.9
Disclosed:
Dec 7, 2013

Download Manager [download-manager] < 2.5.9

unknown

The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.5.9
Fixed in:
2.5.9
Disclosed:
Dec 7, 2013

Download Manager [download-manager] < 3.2.53

unknown

The plugin does not escape the $_SERVER[&#039;REQUEST_URI&#039;] parameter before outputting it back in an attribute of the modal login page (only available when users are not logged in), which could lead to Reflected Cross-Site Scripting in old web browsers.

Affected:
up to 3.2.53
Fixed in:
3.2.53

Download Manager [download-manager] < 3.2.44

unknown

The plugin does not escape a generated URL before outputting it back in an attribute of the login page made by the plugin, leading to Reflected Cross-Site Scripting, which is only exploitable against unauthenticated users

Affected:
up to 3.2.44
Fixed in:
3.2.44

Download Manager [download-manager] < 3.2.13

unknown

The plugin did not have CSRF check in place before saving its Email Template setting, allowing attackers to make a logged in admin change them via a CSRF attack

Affected:
up to 3.2.13
Fixed in:
3.2.13

Download Manager [download-manager] < 3.1.19

unknown

The wpdm_admin_upload_file AJAX action used a blacklist approach to forbid potential dangerous files, such as PHP, from being uploaded. However, other dangerous extensions, like .php4 were not forbidden.

Affected:
up to 3.1.19
Fixed in:
3.1.19

Download Manager [download-manager] < 3.1.22

unknown

The wpdm_settings AJAX action, used the section POST parameter to call the associated settings handler methods dynamically. However, the pluginUpdate() (section=plugin-update) and Privacy() (section=privacy) were missing CSRF checks. Furthermore, the Privacy() function did not ensure that the options to be updated were...

Affected:
up to 3.1.22
Fixed in:
3.1.22

Download Manager [download-manager] < 3.1.23

unknown

The majority of the AJAX actions related to the Asset Manager use the same nonce action (ie the NONCE_KEY constant), and are lacking any authorisation checks. Given that the nonce is available in other pages, accessible by low priviledge users (such as author, or even subscribers depending on the plugin&#039;s feature...

Affected:
up to 3.1.23
Fixed in:
3.1.23

Download Manager [download-manager] < 3.1.18

unknown

The duplicate() method, hooked to the admin_init action did not have any CSRF and authorisation checks, allowing unauthorised users (such as unauthenticated ones) to duplicate arbitrary downloads

Affected:
up to 3.1.18
Fixed in:
3.1.18

Download Manager [download-manager] < 2.9.97

unknown

The WordPress Download Manager WordPress plugin was affected by a Various Sanitisation Issues security vulnerability.

Affected:
up to 2.9.97
Fixed in:
2.9.97

Download Manager [download-manager] < 2.9.61

unknown

The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 2.9.61
Fixed in:
2.9.61

Download Manager [download-manager] < 2.9.46

unknown

The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 2.9.46
Fixed in:
2.9.46

Download Manager [download-manager] < 2.8.8

unknown

Numerous vulnerabilities with WordPress Download Manager free and pro versions. Privilege escalation, directory listing and unauthorised file download.

Affected:
up to 2.8.8
Fixed in:
2.8.8

Download Manager [download-manager] < 2.7.95

unknown

The stored XSS vulnerability allows any authenticated user to inject malicious code via the name of the uploaded file: Example: &lt;svg onload=alert(0)&gt;.jpg The vulnerability exists because the file name is not properly sanitized and this can lead to malicious code injection that will be executed on the ta...

Affected:
up to 2.7.95
Fixed in:
2.7.95

Download Manager [download-manager] < 2.7.5

unknown

The WordPress Download Manager WordPress plugin was affected by a Code Execution / Remote File Inclusion security vulnerability.

Affected:
up to 2.7.5
Fixed in:
2.7.5

Download Manager [download-manager] < 2.2.3

unknown

The WordPress Download Manager WordPress plugin was affected by an admin.php cid Parameter XSS security vulnerability.

Affected:
up to 2.2.3
Fixed in:
2.2.3

Download Manager [download-manager] < 3.2.60

unknown

Update the WordPress Download Manager plugin to the latest available version (at least 3.2.60). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, adver...

Affected:
up to 3.2.60
Fixed in:
3.2.60

Download Manager [download-manager] < 6.3.0

unknown
Affected:
up to 6.3.0
Fixed in:
6.3.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database