plugin

Download Plugin Vulnerabilities

11 known security issues reported for the Download Plugin WordPress plugin. Most recent disclosed Jul 3, 2025.

1 high 4 medium

Running Download Plugin on your site? Check whether your installed version is affected.

Scan your site free

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

high

The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary fil...

CVSS:
7.2
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Jul 3, 2025

CVE-2025-6586 on NVD →

Download Plugin [download-plugin] < 2.2.1

unknown

[en] The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber...

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Oct 23, 2024

CVE-2024-9829 on NVD →

Download Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download

medium

The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber-leve...

CVSS:
6.5
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Oct 22, 2024

CVE-2024-9829 on NVD →

Download Plugin [download-plugin] < 2.0.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
May 28, 2023

CVE-2022-36345 on NVD →

Download Plugin <= 2.0.4 - Cross-Site Request Forgery

medium

The Download Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.4. This is due to missing nonce validation on the dpwap_plugin_download_action, dpwap_theme_download, and dpwap_plugin_multiple_download_func functions. This makes it possible for unauthenticated a...

CVSS:
4.3
Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
May 24, 2023

CVE-2022-36345 on NVD →

Download Plugin [download-plugin] < 2.0.0

unknown

[en] The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Nov 28, 2022

CVE-2021-25059 on NVD →

Download Plugin <= 1.6.2 - Missing Authorization and Sensitive Information Exposure

medium

The Download Plugin plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.6.2 due to missing capability checks on the dpwap_plugin_multiple_download_func function. This makes it possible for authenticated attackers with subscriber-level attackers to create and download arbitrar...

CVSS:
6.5
Affected:
up to 1.6.2
Fixed in:
2.0.0
Disclosed:
Nov 2, 2022

CVE-2021-25059 on NVD →

Download Plugin [download-plugin] < 1.6.2

unknown

[en] The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Nov 23, 2021

CVE-2021-24703 on NVD →

Download Plugin < 1.6.1 - Cross-Site Request Forgery

medium

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

CVSS:
5.7
Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Oct 19, 2021

CVE-2021-24703 on NVD →

Download Plugin [download-plugin] < 1.0.2

unknown

Arbitrary Directory Download Vulnerability was found in WordPress Download Plugin in 1.0.1 version. There's no restriction against directory download in the dpwap_download function. It's a very serious vulnerability because an attacker can download the whole site directory. Update the plugin as soon as possible. Updat...

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Jul 14, 2017

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database