Download Manager < 3.3.66 - Unauthenticated Stored Cross-Site Scripting
high
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected...
- CVSS:
- 7.2
- Affected:
- up to 3.3.66
- Fixed in:
- 3.3.66
- Disclosed:
- Aug 5, 2026
CVE-2026-14292 on NVD →
Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to i...
- CVSS:
- 6.4
- Affected:
- up to 3.3.66
- Fixed in:
- 3.3.67
- Disclosed:
- Jul 31, 2026
CVE-2026-16685 on NVD →
Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 3.3.61
- Fixed in:
- 3.3.62
- Disclosed:
- Jul 8, 2026
CVE-2026-14343 on NVD →
Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 3.3.60
- Fixed in:
- 3.3.61
- Disclosed:
- Jun 30, 2026
CVE-2026-13733 on NVD →
Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verify...
- CVSS:
- 4.3
- Affected:
- up to 3.3.51
- Fixed in:
- 3.3.52
- Disclosed:
- Apr 9, 2026
CVE-2026-4057 on NVD →
Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is e...
- CVSS:
- 6.4
- Affected:
- up to 3.3.52
- Fixed in:
- 3.3.53
- Disclosed:
- Apr 8, 2026
CVE-2026-5357 on NVD →
Download Manager - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter vulnerability
medium
Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter vulnerability
- CVSS:
- 4.3
- Affected:
- up to 3.3.49
- Fixed in:
- 3.3.50
- Disclosed:
- Mar 19, 2026
Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive info...
- CVSS:
- 4.3
- Affected:
- up to 3.3.49
- Fixed in:
- 3.3.50
- Disclosed:
- Mar 18, 2026
CVE-2026-2571 on NVD →
Download Manager <= 3.3.52 - Missing Authorization
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.3.52. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.3.52
- Fixed in:
- 3.3.53
- Disclosed:
- Feb 19, 2026
CVE-2026-39676 on NVD →
Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter
medium
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possibl...
- CVSS:
- 6.1
- Affected:
- up to 3.3.46
- Fixed in:
- 3.3.47
- Disclosed:
- Feb 17, 2026
CVE-2026-1666 on NVD →
Download Manager <= 3.3.53 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 3.3.53
- Fixed in:
- 3.3.54
- Disclosed:
- Feb 10, 2026
CVE-2026-39615 on NVD →
Download Manager [download-manager] < 3.3.41
unknown
[en] The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers...
- Affected:
- up to 3.3.41
- Fixed in:
- 3.3.41
- Disclosed:
- Jan 6, 2026
CVE-2025-15364 on NVD →
Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword
high
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to ch...
- CVSS:
- 7.3
- Affected:
- up to 3.3.40
- Fixed in:
- 3.3.41
- Disclosed:
- Jan 5, 2026
CVE-2025-15364 on NVD →
Download Manager [download-manager] < 3.3.33
unknown
[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscribe...
- Affected:
- up to 3.3.33
- Fixed in:
- 3.3.33
- Disclosed:
- Dec 18, 2025
CVE-2025-13498 on NVD →
Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-lev...
- CVSS:
- 4.3
- Affected:
- up to 3.3.32
- Fixed in:
- 3.3.33
- Disclosed:
- Dec 17, 2025
CVE-2025-13498 on NVD →
Download Manager [download-manager] <= 3.3.32 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32.
- Affected:
- up to 3.3.32
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63070 on NVD →
Download Manager [download-manager] < 3.3.31
unknown
[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletio...
- Affected:
- up to 3.3.31
- Fixed in:
- 3.3.31
- Disclosed:
- Nov 8, 2025
CVE-2025-12177 on NVD →
Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of...
- CVSS:
- 5.3
- Affected:
- up to 3.3.30
- Fixed in:
- 3.3.31
- Disclosed:
- Nov 7, 2025
CVE-2025-12177 on NVD →
Download Manager <= 3.3.32 - Authenticated (Subscriber+) Information Exposure
medium
The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 3.3.32
- Fixed in:
- 3.3.33
- Disclosed:
- Sep 30, 2025
CVE-2025-63070 on NVD →
Download Manager <= 3.3.25 - Unauthenticated Sensitive Information Exposure
medium
The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.3.25
- Fixed in:
- 3.3.26
- Disclosed:
- Sep 26, 2025
CVE-2025-60092 on NVD →
Download Manager <= 3.3.24 - Cross-Site Request Forgery
medium
The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 3.3.24
- Fixed in:
- 3.3.25
- Disclosed:
- Sep 26, 2025
CVE-2025-60093 on NVD →
Download Manager [download-manager] < 3.3.25
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager allows Cross Site Request Forgery. This issue affects Download Manager: from n/a through 3.3.24.
- Affected:
- up to 3.3.25
- Fixed in:
- 3.3.25
- Disclosed:
- Sep 26, 2025
CVE-2025-60093 on NVD →
Download Manager [download-manager] <= 3.3.25 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.24.
- Affected:
- up to 3.3.25
- Fix:
- No patched version reported
- Disclosed:
- Sep 26, 2025
CVE-2025-60092 on NVD →
Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter
medium
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 3.3.23
- Fixed in:
- 3.3.24
- Disclosed:
- Sep 18, 2025
CVE-2025-10146 on NVD →
Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 3.3.18
- Fixed in:
- 3.3.19
- Disclosed:
- Jun 18, 2025
CVE-2025-4367 on NVD →
Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion
high
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the s...
- CVSS:
- 8.8
- Affected:
- up to 3.3.12
- Fixed in:
- 3.3.13
- Disclosed:
- Apr 18, 2025
CVE-2025-3404 on NVD →
Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary...
- CVSS:
- 5.4
- Affected:
- up to 3.3.12
- Fixed in:
- 3.3.13
- Disclosed:
- Apr 17, 2025
CVE-2025-3056 on NVD →
Download Manager [download-manager] < 3.3.07
unknown
[en] The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
- Affected:
- up to 3.3.07
- Fixed in:
- 3.3.07
- Disclosed:
- Mar 16, 2025
CVE-2024-13126 on NVD →
Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite
medium
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory,...
- CVSS:
- 5.4
- Affected:
- up to 3.3.08
- Fixed in:
- 3.3.09
- Disclosed:
- Mar 12, 2025
CVE-2025-1785 on NVD →
Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory
medium
The Download Manager plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 3.3.06. This is due to plugin not providing any access restrictions to the direct in which download files are uploaded. This makes it possible for unauthenticated attackers to access downloads that sh...
- CVSS:
- 5.3
- Affected:
- up to 3.3.06
- Fixed in:
- 3.3.07
- Disclosed:
- Jan 17, 2025
CVE-2024-13126 on NVD →
Download Manager [download-manager] < 3.3.04
unknown
[en] Missing Authorization vulnerability in W3 Eden, Inc. Download Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through 3.3.03.
- Affected:
- up to 3.3.04
- Fixed in:
- 3.3.04
- Disclosed:
- Dec 31, 2024
CVE-2024-56217 on NVD →
Download Manager [download-manager] < 3.3.03
unknown
[en] The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.3.03
- Fixed in:
- 3.3.03
- Disclosed:
- Dec 20, 2024
CVE-2024-10706 on NVD →
Download Manager <= 3.3.03 - Missing Authorization
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.03. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.3.03
- Fixed in:
- 3.3.04
- Disclosed:
- Dec 19, 2024
CVE-2024-56217 on NVD →
Download Manager [download-manager] < 3.3.04
unknown
[en] The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated...
- Affected:
- up to 3.3.04
- Fixed in:
- 3.3.04
- Disclosed:
- Dec 19, 2024
CVE-2024-11740 on NVD →
Download Manager [download-manager] < 3.3.04
unknown
[en] The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected file...
- Affected:
- up to 3.3.04
- Fixed in:
- 3.3.04
- Disclosed:
- Dec 19, 2024
CVE-2024-11768 on NVD →
Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution
high
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attac...
- CVSS:
- 7.3
- Affected:
- up to 3.3.03
- Fixed in:
- 3.3.04
- Disclosed:
- Dec 18, 2024
CVE-2024-11740 on NVD →
Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
- CVSS:
- 5.3
- Affected:
- up to 3.3.03
- Fixed in:
- 3.3.04
- Disclosed:
- Dec 18, 2024
CVE-2024-11768 on NVD →
Download Manager <= 3.3.02 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.02 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 3.3.02
- Fixed in:
- 3.3.03
- Disclosed:
- Nov 29, 2024
CVE-2024-10706 on NVD →
Download Manager [download-manager] < 3.3.00
unknown
[en] The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.
- Affected:
- up to 3.3.00
- Fixed in:
- 3.3.00
- Disclosed:
- Oct 30, 2024
CVE-2024-8444 on NVD →
Download Manager <= 3.2.99 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_login_form' shortcode in all versions up to, and including, 3.2.99 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...
- CVSS:
- 6.4
- Affected:
- up to 3.2.99
- Fixed in:
- 3.3.00
- Disclosed:
- Oct 9, 2024
CVE-2024-8444 on NVD →
Download Manager <= 3.2.98 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.98 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 3.2.98
- Fixed in:
- 3.2.99
- Disclosed:
- Sep 23, 2024
CVE-2024-8284 on NVD →
Download Manager [download-manager] < 3.2.98
unknown
[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers,...
- Affected:
- up to 3.2.98
- Fixed in:
- 3.2.98
- Disclosed:
- Jul 31, 2024
CVE-2024-6208 on NVD →
Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 3.2.97
- Fixed in:
- 3.2.98
- Disclosed:
- Jul 30, 2024
CVE-2024-6208 on NVD →
Download Manager [download-manager] < 3.2.90
unknown
[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.
- Affected:
- up to 3.2.90
- Fixed in:
- 3.2.90
- Disclosed:
- Jun 13, 2024
CVE-2024-2098 on NVD →
Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary
high
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.
- CVSS:
- 7.5
- Affected:
- up to 3.2.89
- Fixed in:
- 3.2.90
- Disclosed:
- Jun 12, 2024
CVE-2024-2098 on NVD →
Download Manager [download-manager] < 3.2.94
unknown
[en] The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attri...
- Affected:
- up to 3.2.94
- Fixed in:
- 3.2.94
- Disclosed:
- Jun 12, 2024
CVE-2024-5266 on NVD →
Download Manager [download-manager] < 3.2.87
unknown
[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to in...
- Affected:
- up to 3.2.87
- Fixed in:
- 3.2.87
- Disclosed:
- Jun 12, 2024
CVE-2024-1766 on NVD →
Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes
medium
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes...
- CVSS:
- 6.4
- Affected:
- up to 3.2.92
- Fixed in:
- 3.2.94
- Disclosed:
- Jun 11, 2024
CVE-2024-5266 on NVD →
Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 3.2.86
- Fixed in:
- 3.2.87
- Disclosed:
- Jun 11, 2024
CVE-2024-1766 on NVD →
Download Manager [download-manager] < 3.2.94
unknown
[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- Affected:
- up to 3.2.94
- Fixed in:
- 3.2.94
- Disclosed:
- Jun 5, 2024
CVE-2024-4001 on NVD →
Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 3.2.93
- Fixed in:
- 3.2.94
- Disclosed:
- Jun 4, 2024
CVE-2024-4001 on NVD →
Download Manager [download-manager] < 3.2.91
unknown
[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...
- Affected:
- up to 3.2.91
- Fixed in:
- 3.2.91
- Disclosed:
- May 31, 2024
CVE-2024-4160 on NVD →
Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 3.2.90
- Fixed in:
- 3.2.91
- Disclosed:
- May 30, 2024
CVE-2024-4160 on NVD →
Download Manager [download-manager] < 3.2.83
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.
- Affected:
- up to 3.2.83
- Fixed in:
- 3.2.83
- Disclosed:
- May 17, 2024
CVE-2024-32131 on NVD →
Download Manager [download-manager] < 3.2.85
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.
- Affected:
- up to 3.2.85
- Fixed in:
- 3.2.85
- Disclosed:
- Mar 19, 2024
CVE-2024-29114 on NVD →
Download Manager <= 3.2.84 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 3.2.84
- Fixed in:
- 3.2.85
- Disclosed:
- Mar 16, 2024
CVE-2024-29114 on NVD →
Download Manager [download-manager] < 3.2.85
unknown
[en] The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
- Affected:
- up to 3.2.85
- Fixed in:
- 3.2.85
- Disclosed:
- Mar 13, 2024
CVE-2023-6785 on NVD →
Download Manager [download-manager] < 3.2.86
unknown
[en] The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contr...
- Affected:
- up to 3.2.86
- Fixed in:
- 3.2.86
- Disclosed:
- Mar 13, 2024
CVE-2023-6954 on NVD →
Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributo...
- CVSS:
- 6.4
- Affected:
- up to 3.2.85
- Fixed in:
- 3.2.86
- Disclosed:
- Feb 28, 2024
CVE-2023-6954 on NVD →
Download Manager <= 3.2.84 - Missing Authorization
medium
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
- CVSS:
- 5.3
- Affected:
- up to 3.2.84
- Fixed in:
- 3.2.85
- Disclosed:
- Feb 28, 2024
CVE-2023-6785 on NVD →
Download Manager [download-manager] < 3.2.83
unknown
[en] The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
- Affected:
- up to 3.2.83
- Fixed in:
- 3.2.83
- Disclosed:
- Jan 1, 2024
CVE-2023-6421 on NVD →
Download Manager <= 3.2.82 - Unauthenticated Password Leak
medium
The Download Manager plugin for WordPress is vulnerable to information Exposure in all versions up to, and including, 3.2.82. This is due to the plugin leaking the password to a protected file when it receives an invalid password. This makes it possible for unauthenticated attackers to gain access to protected files.
- CVSS:
- 5.3
- Affected:
- up to 3.2.82
- Fixed in:
- 3.2.83
- Disclosed:
- Nov 29, 2023
CVE-2023-6421 on NVD →
Download Manager [download-manager] < 3.2.71
unknown
[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...
- Affected:
- up to 3.2.71
- Fixed in:
- 3.2.71
- Disclosed:
- Jun 9, 2023
CVE-2023-2305 on NVD →
Download Manager [download-manager] < 3.2.71
unknown
[en] The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowled...
- Affected:
- up to 3.2.71
- Fixed in:
- 3.2.71
- Disclosed:
- May 30, 2023
CVE-2023-1524 on NVD →
Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 3.2.70
- Fixed in:
- 3.2.71
- Disclosed:
- May 12, 2023
CVE-2023-2305 on NVD →
Download Manager <= 3.2.70 - Insufficient Authorization to Information Disclosure
medium
The Download Manager plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.2.7.0, due to insufficient validation of passwords on password protected files. This makes it possible for authenticated attackers, with access to the downloads area to create a password protected post...
- CVSS:
- 4.3
- Affected:
- up to 3.2.70
- Fixed in:
- 3.2.71
- Disclosed:
- May 8, 2023
CVE-2023-1524 on NVD →
Download Manager [download-manager] < 3.2.60
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
- Affected:
- up to 3.2.60
- Fixed in:
- 3.2.60
- Disclosed:
- Apr 18, 2023
CVE-2022-45836 on NVD →
Download Manager Pro <= 6.2.9 - Unauthenticated Information Disclosure
medium
The Download Manager Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.2.9 due to the plugin leaking the master key. This can allow unauthenticated attackers to retrieve the key and extract sensitive data contained in password protected package files.
- CVSS:
- 5.3
- Affected:
- 4.0 – 6.3.0
- Fixed in:
- 6.3.0
- Disclosed:
- Apr 10, 2023
CVE-2023-1809 on NVD →
Download Manager [download-manager] < 3.2.62
unknown
[en] The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
- Affected:
- up to 3.2.62
- Fixed in:
- 3.2.62
- Disclosed:
- Jan 16, 2023
CVE-2022-4476 on NVD →
Download Manager <= 3.2.61 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 3.2.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 3.2.61
- Fixed in:
- 3.2.62
- Disclosed:
- Dec 20, 2022
CVE-2022-4476 on NVD →
Download Manager <= 3.2.59 - Refleced Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘packages-shortcode-toolbar.php’, 'Shortcodes.php', and 'category-shortcode-toolbar.php' (in both 'src/Package/views/' and 'src/Category/views/') files in versions up to, and including, 3.2.59 due to insufficient input san...
- CVSS:
- 6.1
- Affected:
- up to 3.2.59
- Fixed in:
- 3.2.60
- Disclosed:
- Nov 29, 2022
CVE-2022-45836 on NVD →
Download Manager [download-manager] < 3.2.55
unknown
[en] The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
- Affected:
- up to 3.2.55
- Fixed in:
- 3.2.55
- Disclosed:
- Sep 26, 2022
CVE-2022-2926 on NVD →
Download Manager [download-manager] < 3.2.71
unknown
[en] The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserial...
- Affected:
- up to 3.2.71
- Fixed in:
- 3.2.71
- Disclosed:
- Sep 6, 2022
CVE-2022-2436 on NVD →
Download Manager [download-manager] < 3.2.51
unknown
[en] The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it po...
- Affected:
- up to 3.2.51
- Fixed in:
- 3.2.51
- Disclosed:
- Sep 6, 2022
CVE-2022-2431 on NVD →
Download Manager <= 3.2.54 - Authenticated (Admin+) Path Traversal
medium
The Download Manager plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.2.54 via the File Browser Root field. This makes it possible for administrator-level attackers to list and read arbitrary files and folders outside of the blog directory.
- CVSS:
- 4.9
- Affected:
- up to 3.2.55
- Fixed in:
- 3.2.55
- Disclosed:
- Sep 5, 2022
CVE-2022-2926 on NVD →
Download Manager [download-manager] < 3.2.49
unknown
[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
- Affected:
- up to 3.2.49
- Fixed in:
- 3.2.49
- Disclosed:
- Aug 23, 2022
CVE-2022-36288 on NVD →
Download Manager [download-manager] < 3.2.49
unknown
[en] Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
- Affected:
- up to 3.2.49
- Fixed in:
- 3.2.49
- Disclosed:
- Aug 23, 2022
CVE-2022-34658 on NVD →
Download Manager [download-manager] < 3.2.49
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
- Affected:
- up to 3.2.49
- Fixed in:
- 3.2.49
- Disclosed:
- Aug 22, 2022
CVE-2022-34347 on NVD →
Download Manager [download-manager] < 3.2.50
unknown
[en] The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.
- Affected:
- up to 3.2.50
- Fixed in:
- 3.2.50
- Disclosed:
- Aug 22, 2022
CVE-2022-2362 on NVD →
Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization
high
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize t...
- CVSS:
- 8.8
- Affected:
- up to 3.2.49
- Fixed in:
- 3.2.50
- Disclosed:
- Aug 17, 2022
CVE-2022-2436 on NVD →
Download Manager <= 3.2.53 - Reflected Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 3.2.53
- Fixed in:
- 3.2.54
- Disclosed:
- Aug 4, 2022
Download Manager [download-manager] < 3.2.54
unknown
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- Affected:
- up to 3.2.54
- Fixed in:
- 3.2.54
- Disclosed:
- Aug 4, 2022
Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings Update
high
The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation on the updateTemplateStatus function. This makes it possible for unauthenticated attackers to trigger setting changes forged request grante...
- CVSS:
- 8.8
- Affected:
- up to 3.2.48
- Fixed in:
- 3.2.49
- Disclosed:
- Aug 2, 2022
CVE-2022-34347 on NVD →
Download Manager <= 3.2.48 - Cross-Site Request Forgery
high
The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete stats and clear the plugin's cache via forged request granted they can tric...
- CVSS:
- 8.8
- Affected:
- up to 3.2.48
- Fixed in:
- 3.2.49
- Disclosed:
- Aug 2, 2022
CVE-2022-36288 on NVD →
Download Manager <= 3.2.49 - IP Blocking Bypass
medium
The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 due to the way the visitor's IP address is determined. This allows an unauthenticated attacker to spoof their IP address to obtain access to files that are protected by this functionality.
- CVSS:
- 5.3
- Affected:
- up to 3.2.49
- Fixed in:
- 3.2.50
- Disclosed:
- Aug 1, 2022
CVE-2022-2362 on NVD →
Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion
high
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possibl...
- CVSS:
- 8.8
- Affected:
- up to 3.2.50
- Fixed in:
- 3.2.51
- Disclosed:
- Jul 27, 2022
CVE-2022-2431 on NVD →
Download Manager [download-manager] < 3.2.47
unknown
[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and abo...
- Affected:
- up to 3.2.47
- Fixed in:
- 3.2.47
- Disclosed:
- Jul 18, 2022
CVE-2022-2101 on NVD →
Download Manager [download-manager] < 3.2.44
unknown
[en] The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
- Affected:
- up to 3.2.44
- Fixed in:
- 3.2.44
- Disclosed:
- Jul 17, 2022
CVE-2022-2168 on NVD →
Download Manager <= 3.2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ and 'label' parameters in versions up to, and including, 3.2.48 due to insufficient input sanitization and output escaping when setting lock options for downloadables. This makes it possible for authenticated attacke...
- CVSS:
- 5.4
- Affected:
- up to 3.2.48
- Fixed in:
- 3.2.49
- Disclosed:
- Jul 6, 2022
CVE-2022-34658 on NVD →
Download Manager <= 3.2.43 - Reflected Cross-Site Scripting
medium
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 3.2.43
- Fixed in:
- 3.2.44
- Disclosed:
- Jun 27, 2022
CVE-2022-2168 on NVD →
Download Manager [download-manager] < 3.2.44
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Download Manager plugin (versions <= 3.2.43).
Update the WordPress Download Manager plugin to the latest available version (at least 3.2.44).
- Affected:
- up to 3.2.44
- Fixed in:
- 3.2.44
- Disclosed:
- Jun 27, 2022
Download Manager <= 3.2.43 - Reflected Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...
- CVSS:
- 6.1
- Affected:
- up to 3.2.43
- Fixed in:
- 3.2.44
- Disclosed:
- Jun 23, 2022
Download Manager [download-manager] < 3.2.44
unknown
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...
- Affected:
- up to 3.2.44
- Fixed in:
- 3.2.44
- Disclosed:
- Jun 23, 2022
Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to...
- CVSS:
- 6.4
- Affected:
- up to 3.2.46
- Fixed in:
- 3.2.47
- Disclosed:
- Jun 21, 2022
CVE-2022-2101 on NVD →
Download Manager [download-manager] < 3.2.43
unknown
[en] The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
- Affected:
- up to 3.2.43
- Fixed in:
- 3.2.43
- Disclosed:
- Jun 13, 2022
CVE-2022-1985 on NVD →
Download Manager <= 3.2.42 - Reflected Cross-Site Scripting
medium
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
- CVSS:
- 6.1
- Affected:
- up to 3.2.42
- Fixed in:
- 3.2.43
- Disclosed:
- Jun 2, 2022
CVE-2022-1985 on NVD →
Download Manager [download-manager] < 3.2.39
unknown
[en] The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
- Affected:
- up to 3.2.39
- Fixed in:
- 3.2.39
- Disclosed:
- Apr 11, 2022
CVE-2022-0828 on NVD →
Download Manager <= 3.2.38 - Unauthenticated Brute Force of File Master Key
high
The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
- CVSS:
- 7.5
- Affected:
- up to 3.2.39
- Fixed in:
- 3.2.39
- Disclosed:
- Mar 16, 2022
CVE-2022-0828 on NVD →
Download Manager [download-manager] < 3.2.25
unknown
[en] The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
- Affected:
- up to 3.2.25
- Fixed in:
- 3.2.25
- Disclosed:
- Mar 7, 2022
CVE-2021-25087 on NVD →
Download Manager [download-manager] < 3.2.34
unknown
[en] The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
- Affected:
- up to 3.2.34
- Fixed in:
- 3.2.34
- Disclosed:
- Feb 21, 2022
CVE-2021-25069 on NVD →
Download Manager <= 3.2.34 - Sensitive Information Disclosure
high
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
- CVSS:
- 7.5
- Affected:
- up to 3.2.35
- Fixed in:
- 3.2.35
- Disclosed:
- Feb 2, 2022
CVE-2021-25087 on NVD →
WordPress Download Manager <= 3.2.33 - Authenticated SQL Injection
high
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
- CVSS:
- 8.8
- Affected:
- up to 3.2.34
- Fixed in:
- 3.2.34
- Disclosed:
- Jan 20, 2022
CVE-2021-25069 on NVD →
Download Manager [download-manager] < 3.2.22
unknown
[en] The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber i...
- Affected:
- up to 3.2.22
- Fixed in:
- 3.2.22
- Disclosed:
- Dec 27, 2021
CVE-2021-24969 on NVD →
WordPress Download Manager <= 3.2.21 - Cross-Site Scripting
medium
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is abl...
- CVSS:
- 6.4
- Affected:
- up to 3.2.22
- Fixed in:
- 3.2.22
- Disclosed:
- Nov 29, 2021
CVE-2021-24969 on NVD →
Download Manager [download-manager] < 3.2.16
unknown
[en] The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 3.2.16
- Fixed in:
- 3.2.16
- Disclosed:
- Nov 1, 2021
CVE-2021-24773 on NVD →
WordPress Download Manager <= 3.2.15 - Cross-Site Scripting
medium
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 3.2.16
- Fixed in:
- 3.2.16
- Disclosed:
- Sep 29, 2021
CVE-2021-24773 on NVD →
WordPress Download Manager <= 3.2.12 - Cross-Site Request Forgery
high
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for unauthenticated attackers to save the plugins email settings via a forged r...
- CVSS:
- 7.1
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Aug 9, 2021
Download Manager [download-manager] < 3.2.13
unknown
Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Download Manager plugin (versions <= 3.2.12).
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Aug 9, 2021
Download Manager [download-manager] < 3.2.13
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for unauthenticated attackers to save the plugins email settings via a forged r...
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Aug 9, 2021
Download Manager [download-manager] < 3.1.25
unknown
[en] Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploade...
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.25
- Disclosed:
- Aug 5, 2021
CVE-2021-34638 on NVD →
Download Manager [download-manager] < 3.1.25
unknown
[en] Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.25
- Disclosed:
- Aug 5, 2021
CVE-2021-34639 on NVD →
WordPress Download Manager <= 3.1.24 - Authenticated File Upload
high
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.
- CVSS:
- 7.5
- Affected:
- up to 3.1.24
- Fixed in:
- 3.1.25
- Disclosed:
- Jul 29, 2021
CVE-2021-34639 on NVD →
WordPress Download Manager <= 3.1.24 - Cross-Site Scripting
medium
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded Jav...
- CVSS:
- 6.5
- Affected:
- up to 3.1.24
- Fixed in:
- 3.1.25
- Disclosed:
- Jul 29, 2021
CVE-2021-34638 on NVD →
WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery
high
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a...
- CVSS:
- 8.8
- Affected:
- up to 3.1.22
- Fixed in:
- 3.1.22
- Disclosed:
- Apr 30, 2021
WordPress Download Manager < 3.1.19 - Arbitrary File Upload
high
The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level pr...
- CVSS:
- 8.8
- Affected:
- up to 3.1.19
- Fixed in:
- 3.1.19
- Disclosed:
- Apr 30, 2021
WordPress Download Manager < 3.1.23 - Arbitrary Asset Manager Usage
medium
The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers with low level privileges to reveal the nonce in pages available to them a...
- CVSS:
- 6.3
- Affected:
- up to 3.1.23
- Fixed in:
- 3.1.23
- Disclosed:
- Apr 30, 2021
Download Manager [download-manager] < 3.1.22
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a...
- Affected:
- up to 3.1.22
- Fixed in:
- 3.1.22
- Disclosed:
- Apr 30, 2021
Download Manager [download-manager] < 3.1.23
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers with low level privileges to reveal the nonce in pages available to them a...
- Affected:
- up to 3.1.23
- Fixed in:
- 3.1.23
- Disclosed:
- Apr 30, 2021
Download Manager [download-manager] < 3.1.19
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level pr...
- Affected:
- up to 3.1.19
- Fixed in:
- 3.1.19
- Disclosed:
- Apr 30, 2021
Download Manager <= 3.1.17 - Missing Authorization
medium
The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable si...
- CVSS:
- 5.3
- Affected:
- up to 3.1.18
- Fixed in:
- 3.1.18
- Disclosed:
- Apr 16, 2021
Download Manager [download-manager] < 3.1.17
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable si...
- Affected:
- up to 3.1.17
- Fixed in:
- 3.1.17
- Disclosed:
- Apr 16, 2021
Download Manager [download-manager] < 2.9.94
unknown
[en] The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
- Affected:
- up to 2.9.94
- Fixed in:
- 2.9.94
- Disclosed:
- Sep 3, 2019
CVE-2019-15889 on NVD →
WordPress Download Manager <= 2.9.96 - Cross-Site Scripting
medium
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.9.97
- Fixed in:
- 2.9.97
- Disclosed:
- Jun 16, 2019
Download Manager [download-manager] < 2.9.97
unknown
Multiple vulnerabilities found in WordPress Download Manager plugin (versions <= 2.9.96).
- Affected:
- up to 2.9.97
- Fixed in:
- 2.9.97
- Disclosed:
- Jun 16, 2019
Download Manager [download-manager] < 2.9.97
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.9.97
- Fixed in:
- 2.9.97
- Disclosed:
- Jun 16, 2019
Download Manager [download-manager] < 2.9.94
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by MgThuraMoeMyint on WordPress Download Manager plugin (versions <= 2.9.93).
- Affected:
- up to 2.9.94
- Fixed in:
- 2.9.94
- Disclosed:
- Apr 23, 2019
WordPress Download Manager <= 2.9.93 - Cross-Site Scripting
medium
The WordPress Download Manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.9.94
- Fixed in:
- 2.9.94
- Disclosed:
- Apr 13, 2019
CVE-2019-15889 on NVD →
Download Manager [download-manager] < 2.9.52
unknown
[en] The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
- Affected:
- up to 2.9.52
- Fixed in:
- 2.9.52
- Disclosed:
- Jan 16, 2018
CVE-2017-18032 on NVD →
Download Manager [download-manager] < 2.9.61
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Panagiotis Vagenas in WordPress Download Manager plugin (versions <=2.9.60).
- Affected:
- up to 2.9.61
- Fixed in:
- 2.9.61
- Disclosed:
- Jan 10, 2018
WordPress Download Manager <= 2.9.6 - Cross-Site Request Forgery
medium
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for unauthenticated attackers to install malicious plugins and/or packa...
- CVSS:
- 6.3
- Affected:
- up to 2.9.6
- Fixed in:
- 2.9.61
- Disclosed:
- Jan 9, 2018
Download Manager [download-manager] < 2.9.61
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for unauthenticated attackers to install malicious plugins and/or packa...
- Affected:
- up to 2.9.61
- Fixed in:
- 2.9.61
- Disclosed:
- Jan 9, 2018
Download Manager [download-manager] < 2.7.3
unknown
[en] The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Aug 7, 2017
CVE-2014-9260 on NVD →
WordPress Download Manager < 2.9.51 - Open Redirect
medium
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 2.9.51
- Fixed in:
- 2.9.51
- Disclosed:
- Jul 13, 2017
CVE-2017-2217 on NVD →
Download Manager [download-manager] < 2.9.50
unknown
[en] Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 2.9.50
- Fixed in:
- 2.9.50
- Disclosed:
- Jul 7, 2017
CVE-2017-2216 on NVD →
Download Manager [download-manager] < 2.9.51
unknown
[en] Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- Affected:
- up to 2.9.51
- Fixed in:
- 2.9.51
- Disclosed:
- Jul 7, 2017
CVE-2017-2217 on NVD →
Download Manager [download-manager] < 2.9.46
unknown
Authenticated Arbitrary File Upload Vulnerability exsists in WordPress WordPress Download Manager plugin <= 2.8.97 . It doesn't check what type of files you can upload so an attacker can upload .PHP files.
Update the plugin.
- Affected:
- up to 2.9.46
- Fixed in:
- 2.9.46
- Disclosed:
- Jun 27, 2017
WordPress Download Manager <= 2.9.51 - Cross-Site Scripting
medium
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
- CVSS:
- 6.1
- Affected:
- up to 2.9.51
- Fixed in:
- 2.9.52
- Disclosed:
- Jun 16, 2017
CVE-2017-18032 on NVD →
WordPress Download Manager <= 2.9.49 - Reflected Cross-Site Scripting
medium
The WordPress Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in versions up to, and including, 2.9.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 2.9.50
- Fixed in:
- 2.9.50
- Disclosed:
- Jun 13, 2017
CVE-2017-2216 on NVD →
WordPress Download Manager <= 2.9.45 - Cross-Site Request Forgery
high
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it possible for unauthenticated attackers to modify administrative settings via a f...
- CVSS:
- 8.8
- Affected:
- up to 2.9.45
- Fixed in:
- 2.9.46
- Disclosed:
- Mar 1, 2017
Download Manager [download-manager] < 2.9.46
unknown
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it possible for unauthenticated attackers to modify administrative settings via a f...
- Affected:
- up to 2.9.46
- Fixed in:
- 2.9.46
- Disclosed:
- Mar 1, 2017
Download Manager <= 2.8.7 - Missing Authorization
critical
The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary files with posts and subsequently download those files caus...
- CVSS:
- 9.1
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 19, 2016
Download Manager <= 2.8.7 - Privilege Escalation
medium
The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.
- CVSS:
- 6.5
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 19, 2016
Download Manager <= 2.8.7 - Sensitive Information Disclosure via Directory Listing
medium
The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers to read all of the files listed in that directory.
- CVSS:
- 5.3
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 19, 2016
Download Manager [download-manager] < 2.8.8
unknown
This plugin is prone to privilege escalation, unauthenticated directory listings and unauthenticated post updating vulnerabilities.
Update the plugin.
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 19, 2016
Download Manager [download-manager] < 2.8.8
unknown
The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers to read all of the files listed in that directory.
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 19, 2016
Download Manager [download-manager] < 2.8.8
unknown
The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 19, 2016
Download Manager [download-manager] < 2.8.8
unknown
The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary files with posts and subsequently download those files caus...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 19, 2016
Download Manager [download-manager] < 2.7.95
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.7.95
- Fixed in:
- 2.7.95
- Disclosed:
- Dec 20, 2015
WordPress Download Manager <= 2.7.94 - Stored Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 2.7.94
- Fixed in:
- 2.7.95
- Disclosed:
- Jul 16, 2015
Download Manager [download-manager] < 2.7.95
unknown
Download Manager Free and Pro is prone to an authenticated stored XSS that allows an attacker to create new download package and upload files, called <svg onload=alert(0)>.jpg. This vulnerability works, when user try to edit this download package.
Upgrade to the latest version.
- Affected:
- up to 2.7.95
- Fixed in:
- 2.7.95
- Disclosed:
- Jul 16, 2015
Download Manager [download-manager] < 2.7.95
unknown
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages t...
- Affected:
- up to 2.7.95
- Fixed in:
- 2.7.95
- Disclosed:
- Jul 16, 2015
Download Manager [download-manager] < 2.2.3
unknown
This plugin is prone to admin.php cid parameter cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- May 15, 2015
WordPress Download Manager <= 2.7.4 - Remote Code Execution
critical
The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Dec 15, 2014
Download Manager [download-manager] >= 2.7.0 - <= 2.7.4
unknown
Download Manager plugin is prone to a remote code execution vulnerability via "/download-manager/wpdm-core.php". It allows attackers to execute arbitrary PHP code.
Upgrade the plugin.
- Affected:
- 2.7.0 – 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Dec 15, 2014
Download Manager [download-manager] < 2.7.5
unknown
The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Dec 15, 2014
WordPress Download Manager <= 2.7.2 - Authenticated Arbitrary Options Update
high
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
- CVSS:
- 8.1
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Nov 24, 2014
CVE-2014-9260 on NVD →
Download Manager [download-manager] < 2.7
unknown
[en] Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Nov 4, 2014
CVE-2014-8585 on NVD →
Download Manager <= 2.2.2 - Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's brow...
- CVSS:
- 6.1
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Aug 1, 2014
Download Manager [download-manager] < 2.2.3
unknown
The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's brow...
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Aug 1, 2014
Download Manager [download-manager] < 2.5.9
unknown
[en] Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
- Affected:
- up to 2.5.9
- Fixed in:
- 2.5.9
- Disclosed:
- Feb 6, 2014
CVE-2013-7319 on NVD →
Download Manager < 2.5.9 - Stored Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
- CVSS:
- 7.2
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.9
- Disclosed:
- Dec 8, 2013
CVE-2013-7319 on NVD →
Download Manager <= 2.5.8 - Cross-Site Scripting
medium
The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.3
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.9
- Disclosed:
- Dec 7, 2013
Download Manager [download-manager] < 2.5.9
unknown
The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.5.9
- Fixed in:
- 2.5.9
- Disclosed:
- Dec 7, 2013
Download Manager [download-manager] < 3.2.53
unknown
The plugin does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute of the modal login page (only available when users are not logged in), which could lead to Reflected Cross-Site Scripting in old web browsers.
- Affected:
- up to 3.2.53
- Fixed in:
- 3.2.53
Download Manager [download-manager] < 3.2.44
unknown
The plugin does not escape a generated URL before outputting it back in an attribute of the login page made by the plugin, leading to Reflected Cross-Site Scripting, which is only exploitable against unauthenticated users
- Affected:
- up to 3.2.44
- Fixed in:
- 3.2.44
Download Manager [download-manager] < 3.2.13
unknown
The plugin did not have CSRF check in place before saving its Email Template setting, allowing attackers to make a logged in admin change them via a CSRF attack
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
Download Manager [download-manager] < 3.1.19
unknown
The wpdm_admin_upload_file AJAX action used a blacklist approach to forbid potential dangerous files, such as PHP, from being uploaded. However, other dangerous extensions, like .php4 were not forbidden.
- Affected:
- up to 3.1.19
- Fixed in:
- 3.1.19
Download Manager [download-manager] < 3.1.22
unknown
The wpdm_settings AJAX action, used the section POST parameter to call the associated settings handler methods dynamically. However, the pluginUpdate() (section=plugin-update) and Privacy() (section=privacy) were missing CSRF checks. Furthermore, the Privacy() function did not ensure that the options to be updated were...
- Affected:
- up to 3.1.22
- Fixed in:
- 3.1.22
Download Manager [download-manager] < 3.1.23
unknown
The majority of the AJAX actions related to the Asset Manager use the same nonce action (ie the NONCE_KEY constant), and are lacking any authorisation checks. Given that the nonce is available in other pages, accessible by low priviledge users (such as author, or even subscribers depending on the plugin's feature...
- Affected:
- up to 3.1.23
- Fixed in:
- 3.1.23
Download Manager [download-manager] < 3.1.18
unknown
The duplicate() method, hooked to the admin_init action did not have any CSRF and authorisation checks, allowing unauthorised users (such as unauthenticated ones) to duplicate arbitrary downloads
- Affected:
- up to 3.1.18
- Fixed in:
- 3.1.18
Download Manager [download-manager] < 2.9.97
unknown
The WordPress Download Manager WordPress plugin was affected by a Various Sanitisation Issues security vulnerability.
- Affected:
- up to 2.9.97
- Fixed in:
- 2.9.97
Download Manager [download-manager] < 2.9.61
unknown
The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
- Affected:
- up to 2.9.61
- Fixed in:
- 2.9.61
Download Manager [download-manager] < 2.9.46
unknown
The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
- Affected:
- up to 2.9.46
- Fixed in:
- 2.9.46
Download Manager [download-manager] < 2.8.8
unknown
Numerous vulnerabilities with WordPress Download Manager free and pro versions. Privilege escalation, directory listing and unauthorised file download.
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
Download Manager [download-manager] < 2.7.95
unknown
The stored XSS vulnerability allows any authenticated user to inject malicious code via the name of the uploaded file:
Example: <svg onload=alert(0)>.jpg
The vulnerability exists because the file name is not properly sanitized
and this can lead to malicious code injection that will be executed on the
ta...
- Affected:
- up to 2.7.95
- Fixed in:
- 2.7.95
Download Manager [download-manager] < 2.7.5
unknown
The WordPress Download Manager WordPress plugin was affected by a Code Execution / Remote File Inclusion security vulnerability.
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
Download Manager [download-manager] < 2.2.3
unknown
The WordPress Download Manager WordPress plugin was affected by an admin.php cid Parameter XSS security vulnerability.
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
Download Manager [download-manager] < 3.2.60
unknown
Update the WordPress Download Manager plugin to the latest available version (at least 3.2.60).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, adver...
- Affected:
- up to 3.2.60
- Fixed in:
- 3.2.60
Download Manager [download-manager] < 6.3.0
unknown
- Affected:
- up to 6.3.0
- Fixed in:
- 6.3.0
Download Manager [download-manager] < 3.2.99
unknown
- Affected:
- up to 3.2.99
- Fixed in:
- 3.2.99
CVE-2024-8284 on NVD →
Download Manager [download-manager] < 3.3.09
unknown
- Affected:
- up to 3.3.09
- Fixed in:
- 3.3.09
CVE-2025-1785 on NVD →
Download Manager [download-manager] < 3.3.13
unknown
- Affected:
- up to 3.3.13
- Fixed in:
- 3.3.13
CVE-2025-3056 on NVD →
Download Manager [download-manager] < 3.3.13
unknown
- Affected:
- up to 3.3.13
- Fixed in:
- 3.3.13
CVE-2025-3404 on NVD →
Download Manager [download-manager] < 3.3.19
unknown
- Affected:
- up to 3.3.19
- Fixed in:
- 3.3.19
CVE-2025-4367 on NVD →