WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter
medium
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in the file deletion functionality. This is due to insufficient validation of user-supplied file paths, allowing directory traversal sequences. This makes it possible for authe...
- CVSS:
- 6.5
- Affected:
- up to 1.69
- Fixed in:
- 1.69.1
- Disclosed:
- Feb 17, 2026
CVE-2026-2426 on NVD →
WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter
low
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass the WP_CONTENT_DIR prefix chec...
- CVSS:
- 2.7
- Affected:
- up to 1.69
- Fixed in:
- 1.69.1
- Disclosed:
- Feb 17, 2026
CVE-2026-2419 on NVD →
WP-DownloadManager <= 1.68.11 - Authenticated (Admin+) Arbitrary File Upload
high
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on...
- CVSS:
- 7.2
- Affected:
- up to 1.68.11
- Fixed in:
- 1.69
- Disclosed:
- Sep 25, 2025
CVE-2025-10747 on NVD →
WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Read
medium
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access and...
- CVSS:
- 4.9
- Affected:
- up to 1.68.10
- Fixed in:
- 1.68.11
- Disclosed:
- Jun 10, 2025
CVE-2025-4798 on NVD →
WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Deletion
high
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary fi...
- CVSS:
- 7.2
- Affected:
- up to 1.68.10
- Fixed in:
- 1.68.11
- Disclosed:
- Jun 10, 2025
CVE-2025-4799 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.68.9
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaMerZ’ Chan WP-DownloadManager allows Reflected XSS.This issue affects WP-DownloadManager: from n/a through 1.68.8.
- Affected:
- up to 1.68.9
- Fixed in:
- 1.68.9
- Disclosed:
- Oct 6, 2024
CVE-2024-47341 on NVD →
WP-DownloadManager <= 1.68.8 - Reflected Cross-Site Scripting
medium
The WP-DownloadManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.68.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 1.68.8
- Fixed in:
- 1.68.9
- Disclosed:
- Sep 27, 2024
CVE-2024-47341 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.68.7
unknown
[en] Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories.
- Affected:
- up to 1.68.7
- Fixed in:
- 1.68.7
- Disclosed:
- Mar 25, 2022
CVE-2022-25606 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.68.7
unknown
[en] Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.
- Affected:
- up to 1.68.7
- Fixed in:
- 1.68.7
- Disclosed:
- Mar 18, 2022
CVE-2022-25605 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.68.7
unknown
[en] Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions.
- Affected:
- up to 1.68.7
- Fixed in:
- 1.68.7
- Disclosed:
- Mar 18, 2022
CVE-2021-44760 on NVD →
WP-DownloadManager plugin <= 1.68.6 - Stored Cross-Site Scripting
medium
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.
- CVSS:
- 4.8
- Affected:
- up to 1.68.7
- Fixed in:
- 1.68.7
- Disclosed:
- Jan 12, 2022
CVE-2022-25605 on NVD →
WP-DownloadManager <= 1.68.6 - Stored Cross-Site Scripting
medium
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories.
- CVSS:
- 4.8
- Affected:
- up to 1.68.7
- Fixed in:
- 1.68.7
- Disclosed:
- Jan 10, 2022
CVE-2022-25606 on NVD →
WP-DownloadManager plugin <= 1.68.6 - Reflected Cross-Site Scripting
medium
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6).
- CVSS:
- 4.8
- Affected:
- up to 1.68.6
- Fixed in:
- 1.68.7
- Disclosed:
- Dec 28, 2021
CVE-2021-44760 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.68.6
unknown
[en] Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
- Affected:
- up to 1.68.6
- Fixed in:
- 1.68.6
- Disclosed:
- Jul 7, 2021
CVE-2020-24141 on NVD →
WP-DownloadManager <= 1.68.4 - Server-Side Request Forgery
medium
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
- CVSS:
- 5.3
- Affected:
- up to 1.68.5
- Fixed in:
- 1.68.5
- Disclosed:
- Apr 13, 2021
CVE-2020-24141 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.61
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- Affected:
- up to 1.61
- Fixed in:
- 1.61
- Disclosed:
- Apr 19, 2013
CVE-2013-2697 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.68.11
unknown
- Affected:
- up to 1.68.11
- Fixed in:
- 1.68.11
CVE-2025-4798 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.68.11
unknown
- Affected:
- up to 1.68.11
- Fixed in:
- 1.68.11
CVE-2025-4799 on NVD →
WP-DownloadManager [wp-downloadmanager] < 1.69
unknown
- Affected:
- up to 1.69
- Fixed in:
- 1.69
CVE-2025-10747 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database