Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload
high
The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary fil...
- CVSS:
- 7.2
- Affected:
- up to 2.2.8
- Fixed in:
- 2.2.9
- Disclosed:
- Jul 3, 2025
CVE-2025-6586 on NVD →
Download Plugin [download-plugin] < 2.2.1
unknown
[en] The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber...
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Oct 23, 2024
CVE-2024-9829 on NVD →
Download Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download
medium
The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber-leve...
- CVSS:
- 6.5
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Oct 22, 2024
CVE-2024-9829 on NVD →
Download Plugin [download-plugin] < 2.0.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- May 28, 2023
CVE-2022-36345 on NVD →
Download Plugin <= 2.0.4 - Cross-Site Request Forgery
medium
The Download Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.4. This is due to missing nonce validation on the dpwap_plugin_download_action, dpwap_theme_download, and dpwap_plugin_multiple_download_func functions. This makes it possible for unauthenticated a...
- CVSS:
- 4.3
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- May 24, 2023
CVE-2022-36345 on NVD →
Download Plugin [download-plugin] < 2.0.0
unknown
[en] The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Nov 28, 2022
CVE-2021-25059 on NVD →
Download Plugin <= 1.6.2 - Missing Authorization and Sensitive Information Exposure
medium
The Download Plugin plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.6.2 due to missing capability checks on the dpwap_plugin_multiple_download_func function. This makes it possible for authenticated attackers with subscriber-level attackers to create and download arbitrar...
- CVSS:
- 6.5
- Affected:
- up to 1.6.2
- Fixed in:
- 2.0.0
- Disclosed:
- Nov 2, 2022
CVE-2021-25059 on NVD →
Download Plugin [download-plugin] < 1.6.2
unknown
[en] The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Nov 23, 2021
CVE-2021-24703 on NVD →
Download Plugin < 1.6.1 - Cross-Site Request Forgery
medium
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
- CVSS:
- 5.7
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Oct 19, 2021
CVE-2021-24703 on NVD →
Download Plugin [download-plugin] < 1.0.2
unknown
Arbitrary Directory Download Vulnerability was found in WordPress Download Plugin in 1.0.1 version. There's no restriction against directory download in the dpwap_download function. It's a very serious vulnerability because an attacker can download the whole site directory. Update the plugin as soon as possible.
Updat...
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Jul 14, 2017
Download Plugin [download-plugin] < 2.2.9
unknown
- Affected:
- up to 2.2.9
- Fixed in:
- 2.2.9
CVE-2025-6586 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database