cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fordownload-manager download-manager

Direction: ascending
Jun 07, 2024

Download Manager # CVE-2021-24773

CVE, Research URL

CVE-2021-24773

Application

Download Manager

Date
Nov 01, 2021
Research Description
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed
Affected versions
max 3.2.16.
Status
vulnerable

Download Manager # CVE-2017-2216

CVE, Research URL

CVE-2017-2216

Application

Download Manager

Date
Jul 07, 2017
Research Description
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
max 2.9.50.
Status
vulnerable

Download Manager # CVE-2021-25087

CVE, Research URL

CVE-2021-25087

Application

Download Manager

Date
Mar 07, 2022
Research Description
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
Affected versions
max 3.2.25.
Status
vulnerable

Download Manager # CVE-2021-25069

CVE, Research URL

CVE-2021-25069

Application

Download Manager

Date
Feb 21, 2022
Research Description
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
Affected versions
max 3.2.34.
Status
vulnerable

Download Manager # CVE-2021-24969

CVE, Research URL

CVE-2021-24969

Application

Download Manager

Date
Dec 27, 2021
Research Description
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks
Affected versions
max 3.2.22.
Status
vulnerable

Download Manager # CVE-2021-34638

CVE, Research URL

CVE-2021-34638

Application

Download Manager

Date
Aug 06, 2021
Research Description
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.
Affected versions
max 3.1.25.
Status
vulnerable

Download Manager # CVE-2019-15889

CVE, Research URL

CVE-2019-15889

Application

Download Manager

Date
Sep 03, 2019
Research Description
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
Affected versions
max 2.9.94.
Status
vulnerable

Download Manager # CVE-2017-18032

CVE, Research URL

CVE-2017-18032

Application

Download Manager

Date
Jan 16, 2018
Research Description
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
Affected versions
max 2.9.52.
Status
vulnerable

Download Manager # CVE-2014-8585

CVE, Research URL

CVE-2014-8585

Application

Download Manager

Date
Nov 04, 2014
Research Description
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
Affected versions
max 2.7.
Status
vulnerable

Download Manager # CVE-2022-0828

CVE, Research URL

CVE-2022-0828

Application

Download Manager

Date
Apr 11, 2022
Research Description
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
Affected versions
max 3.2.39.
Status
vulnerable

Download Manager # CVE-2021-34639

CVE, Research URL

CVE-2021-34639

Application

Download Manager

Date
Aug 06, 2021
Research Description
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.
Affected versions
max 3.1.25.
Status
vulnerable

Download Manager # CVE-2014-9260

CVE, Research URL

CVE-2014-9260

Application

Download Manager

Date
Aug 07, 2017
Research Description
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
Affected versions
max 2.7.3.
Status
vulnerable

Download Manager # CVE-2017-2217

CVE, Research URL

CVE-2017-2217

Application

Download Manager

Date
Jul 07, 2017
Research Description
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Affected versions
max 2.9.51.
Status
vulnerable

Download Manager # CVE-2013-7319

CVE, Research URL

CVE-2013-7319

Application

Download Manager

Date
Feb 06, 2014
Research Description
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
Affected versions
max 2.5.9.
Status
vulnerable

Download Manager # CVE-2022-1985

CVE, Research URL

CVE-2022-1985

Application

Download Manager

Date
Jun 13, 2022
Research Description
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
Affected versions
Min 2.7.0, max 3.2.43.
Status
vulnerable

Download Manager # CVE-2022-2926

CVE, Research URL

CVE-2022-2926

Application

Download Manager

Date
Sep 26, 2022
Research Description
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
Affected versions
max 3.2.55.
Status
vulnerable

Download Manager # CVE-2022-34658

CVE, Research URL

CVE-2022-34658

Application

Download Manager

Date
Aug 23, 2022
Research Description
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Affected versions
max 3.2.49.
Status
vulnerable

Download Manager # CVE-2022-34347

CVE, Research URL

CVE-2022-34347

Application

Download Manager

Date
Aug 22, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Affected versions
max 3.2.49.
Status
vulnerable

Download Manager # CVE-2022-2362

CVE, Research URL

CVE-2022-2362

Application

Download Manager

Date
Aug 22, 2022
Research Description
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.
Affected versions
max 3.2.50.
Status
vulnerable

Download Manager # CVE-2022-2431

CVE, Research URL

CVE-2022-2431

Application

Download Manager

Date
Sep 06, 2022
Research Description
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the /wp-config.php file which will reset the installation and make it possible for an attacker to achieve remote code execution on the server.
Affected versions
max 3.2.51.
Status
vulnerable

Download Manager # CVE-2022-2101

CVE, Research URL

CVE-2022-2101

Application

Download Manager

Date
Jul 18, 2022
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page.
Affected versions
max 3.2.47.
Status
vulnerable

Download Manager # CVE-2022-2168

CVE, Research URL

CVE-2022-2168

Application

Download Manager

Date
Jul 17, 2022
Research Description
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
Affected versions
max 3.2.44.
Status
vulnerable

Download Manager # CVE-2022-36288

CVE, Research URL

CVE-2022-36288

Application

Download Manager

Date
Aug 23, 2022
Research Description
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Affected versions
max 3.2.49.
Status
vulnerable

Download Manager # CVE-2022-2436

CVE, Research URL

CVE-2022-2436

Application

Download Manager

Date
Sep 06, 2022
Research Description
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Affected versions
max 3.2.71.
Status
vulnerable

Download Manager # CVE-2022-4476

CVE, Research URL

CVE-2022-4476

Application

Download Manager

Date
Jan 16, 2023
Research Description
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
Affected versions
max 3.2.62.
Status
vulnerable

Download Manager # CVE-2022-45836

CVE, Research URL

CVE-2022-45836

Application

Download Manager

Date
Apr 18, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
Affected versions
max 3.2.60.
Status
vulnerable

Download Manager # CVE-2023-6785

CVE, Research URL

CVE-2023-6785

Application

Download Manager

Date
Mar 13, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
Affected versions
max 3.2.85.
Status
vulnerable

Download Manager # CVE-2023-6954

CVE, Research URL

CVE-2023-6954

Application

Download Manager

Date
Mar 13, 2024
Research Description
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.2.86.
Status
vulnerable

Download Manager # CVE-2024-29114

CVE, Research URL

CVE-2024-29114

Application

Download Manager

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.
Affected versions
max 3.2.85.
Status
vulnerable

Download Manager # CVE-2023-2305

CVE, Research URL

CVE-2023-2305

Application

Download Manager

Date
Jun 09, 2023
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.2.71.
Status
vulnerable

Download Manager # CVE-2023-1809

CVE, Research URL

CVE-2023-1809

Application

Download Manager

Date
May 02, 2023
Research Description
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
Affected versions
max 3.2.71.
Status
vulnerable

Download Manager # CVE-2023-1524

CVE, Research URL

CVE-2023-1524

Application

Download Manager

Date
May 30, 2023
Research Description
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.
Affected versions
max 3.2.71.
Status
vulnerable

Download Manager # CVE-2023-6421

CVE, Research URL

CVE-2023-6421

Application

Download Manager

Date
Jan 01, 2024
Research Description
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
Affected versions
max 3.2.83.
Status
vulnerable

Download Manager # CVE-2024-32131

CVE, Research URL

CVE-2024-32131

Application

Download Manager

Date
May 17, 2024
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.
Affected versions
max 3.2.83.
Status
vulnerable

Download Manager # CVE-2024-4160

CVE, Research URL

CVE-2024-4160

Application

Download Manager

Date
May 31, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.2.91.
Status
vulnerable
Jun 10, 2024

Download Manager # CVE-2024-4001

CVE, Research URL

CVE-2024-4001

Application

Download Manager

Date
Jun 05, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.2.94.
Status
vulnerable
Jun 13, 2024

Download Manager # CVE-2024-1766

CVE, Research URL

CVE-2024-1766

Application

Download Manager

Date
Jun 12, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.
Affected versions
max 3.2.87.
Status
vulnerable

Download Manager # CVE-2024-5266

CVE, Research URL

CVE-2024-5266

Application

Download Manager

Date
Jun 12, 2024
Research Description
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.2.94.
Status
vulnerable
Jul 22, 2024

Download Manager # CVE-2024-2098

CVE, Research URL

CVE-2024-2098

Application

Download Manager

Date
Jun 13, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.
Affected versions
max 3.2.90.
Status
vulnerable
Aug 01, 2024

Download Manager # CVE-2024-6208

CVE, Research URL

CVE-2024-6208

Application

Download Manager

Date
Jul 31, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.2.98.
Status
vulnerable
Oct 20, 2024

Download Manager # CVE-2024-8284

CVE, Research URL

CVE-2024-8284

Application

Download Manager

Date
May 16, 2025
Research Description
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Affected versions
max 3.2.99.
Status
vulnerable
Oct 31, 2024

Download Manager # CVE-2024-8444

CVE, Research URL

CVE-2024-8444

Application

Download Manager

Date
Oct 30, 2024
Research Description
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.
Affected versions
max 3.3.00.
Status
vulnerable
Dec 21, 2024

Download Manager # CVE-2024-11768

CVE, Research URL

CVE-2024-11768

Application

Download Manager

Date
Dec 19, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Affected versions
max 3.3.04.
Status
vulnerable

Download Manager # CVE-2024-11740

CVE, Research URL

CVE-2024-11740

Application

Download Manager

Date
Dec 19, 2024
Research Description
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected versions
max 3.3.04.
Status
vulnerable
Jan 02, 2025

Download Manager # CVE-2024-56217

CVE, Research URL

CVE-2024-56217

Application

Download Manager

Date
Dec 31, 2024
Research Description
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.03.
Affected versions
max 3.3.04.
Status
vulnerable
Mar 14, 2025

Download Manager # CVE-2025-1785

CVE, Research URL

CVE-2025-1785

Application

Download Manager

Date
Mar 13, 2025
Research Description
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.
Affected versions
max 3.3.09.
Status
vulnerable
Mar 19, 2025

Download Manager # CVE-2024-13126

CVE, Research URL

CVE-2024-13126

Application

Download Manager

Date
Mar 16, 2025
Research Description
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
Affected versions
max 3.3.07.
Status
vulnerable
Apr 19, 2025

Download Manager # CVE-2025-3056

CVE, Research URL

CVE-2025-3056

Application

Download Manager

Date
Apr 18, 2025
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected versions
max 3.3.13.
Status
vulnerable

Download Manager # CVE-2025-3404

CVE, Research URL

CVE-2025-3404

Application

Download Manager

Date
Apr 19, 2025
Research Description
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected versions
max 3.3.13.
Status
vulnerable
May 06, 2025

Download Manager # CVE-2024-10706

CVE, Research URL

CVE-2024-10706

Application

Download Manager

Date
Dec 20, 2024
Research Description
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 3.3.03.
Status
vulnerable
Jul 02, 2025

Download Manager # CVE-2025-4367

CVE, Research URL

CVE-2025-4367

Application

Download Manager

Date
Jun 19, 2025
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.3.19.
Status
vulnerable
Oct 11, 2025

Download Manager # CVE-2025-60092

CVE, Research URL

CVE-2025-60092

Application

Download Manager

Date
Sep 26, 2025
Research Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.25.
Affected versions
max 3.3.26.
Status
vulnerable

Download Manager # CVE-2025-60093

CVE, Research URL

CVE-2025-60093

Application

Download Manager

Date
Sep 26, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request Forgery.This issue affects Download Manager: from n/a through <= 3.3.24.
Affected versions
max 3.3.25.
Status
vulnerable
Dec 10, 2025

Download Manager # CVE-2025-63070

CVE, Research URL

CVE-2025-63070

Application

Download Manager

Date
Dec 09, 2025
Research Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32.
Affected versions
max 3.3.33.
Status
vulnerable
Jan 28, 2026

Download Manager # CVE-2025-15364

CVE, Research URL

CVE-2025-15364

Application

Download Manager

Date
Jan 06, 2026
Research Description
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.
Affected versions
max 3.3.41.
Status
vulnerable

Download Manager # CVE-2025-13498

CVE, Research URL

CVE-2025-13498

Application

Download Manager

Date
Dec 18, 2025
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.
Affected versions
max 3.3.33.
Status
vulnerable
Apr 14, 2026

Download Manager # CVE-2026-39615

CVE, Research URL

CVE-2026-39615

Application

Download Manager

Date
Apr 08, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through <= 3.3.53.
Affected versions
max 3.3.54.
Status
vulnerable

Download Manager # CVE-2026-2571

CVE, Research URL

CVE-2026-2571

Application

Download Manager

Date
Mar 19, 2026
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates.
Affected versions
max 3.3.50.
Status
vulnerable

Download Manager # CVE-2026-39676

CVE, Research URL

CVE-2026-39676

Application

Download Manager

Date
Apr 08, 2026
Research Description
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.
Affected versions
max 3.3.53.
Status
vulnerable

Download Manager # CVE-2026-4057

CVE, Research URL

CVE-2026-4057

Application

Download Manager

Date
Apr 10, 2026
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verifying post ownership via `current_user_can('edit_post', $id)`, and the destructive operations executing before the admin-level check in `mediaAccessControl()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to strip all protection metadata (password, access restrictions, private flag) from any media file they do not own, making admin-protected files publicly accessible via their direct URL.
Affected versions
max 3.3.52.
Status
vulnerable

Download Manager # CVE-2026-5357

CVE, Research URL

CVE-2026-5357

Application

Download Manager

Date
Apr 09, 2026
Research Description
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is extracted without sanitization in the members() function and stored via update_post_meta(), then echoed directly into an HTML id attribute in the members.php template without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.
Affected versions
max 3.3.53.
Status
vulnerable
Apr 15, 2026

Download Manager # CVE-2026-1666

CVE, Research URL

CVE-2026-1666

Application

Download Manager

Date
Feb 18, 2026
Research Description
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 3.3.47.
Status
vulnerable
Apr 23, 2026

Download Manager # CVE-2025-10146

CVE, Research URL

CVE-2025-10146

Application

Download Manager

Date
Sep 19, 2025
Research Description
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 3.3.24.
Status
vulnerable
Jun 14, 2026

Download Manager # CVE-2025-12177

CVE, Research URL

CVE-2025-12177

Application

Download Manager

Date
Nov 08, 2025
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.
Affected versions
max 3.3.31.
Status
vulnerable
Jun 16, 2026

Download Manager # dcd868a17d34d1cc7c03e424780d2c8efb3bb492

Application

Download Manager

Date
Jun 27, 2017
Research Description
Download Manager [download-manager] < 2.9.46 WordPress Download Manager plugin <= 2.8.97 - Authenticated Arbitrary File Upload Vulnerability Authenticated Arbitrary File Upload Vulnerability exsists in WordPress WordPress Download Manager plugin <= 2.8.97 . It doesn't check what type of files you can upload so an attacker can upload .PHP files. Update the plugin.
Affected versions
max 2.9.46.
Status
vulnerable

Download Manager # a8d63261acfeea228c370d3682acda5dfc385b49

Application

Download Manager

Date
Aug 09, 2021
Research Description
Download Manager [download-manager] < 3.2.13 WordPress Download Manager plugin <= 3.2.12 - Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Download Manager plugin (versions <= 3.2.12).
Affected versions
max 3.2.13.
Status
vulnerable

Download Manager # 48e30762d6539a7eee45478972c929e51e64166d

Application

Download Manager

Date
Jun 16, 2019
Research Description
Download Manager [download-manager] < 2.9.97 WordPress Download Manager plugin <= 2.9.96 - Multiple vulnerabilities Multiple vulnerabilities found in WordPress Download Manager plugin (versions <= 2.9.96).
Affected versions
max 2.9.97.
Status
vulnerable

Download Manager # 22a2e7b0e1328bdfcd9abdf7258c7bf9cdb14680

Application

Download Manager

Date
Jan 10, 2018
Research Description
Download Manager [download-manager] < 2.9.61 WordPress Download Manager plugin <=2.9.60 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found by Panagiotis Vagenas in WordPress Download Manager plugin (versions <=2.9.60).
Affected versions
max 2.9.61.
Status
vulnerable

Download Manager # 43f75deeeade722676f3b4836a0f47b56479e1c3

Application

Download Manager

Date
Jan 19, 2016
Research Description
Download Manager [download-manager] < 2.8.8 WordPress Download Manager Plugin <= 2.8.7 - Multiple Vulnerabilities This plugin is prone to privilege escalation, unauthenticated directory listings and unauthenticated post updating vulnerabilities. Update the plugin.
Affected versions
max 2.8.8.
Status
vulnerable

Download Manager # dc77633354921d8fde420d9502ad22bee58a2399

Application

Download Manager

Date
Jul 16, 2015
Research Description
Download Manager [download-manager] < 2.7.95 WordPress Download Manager Free 2.7.94 & Pro 4 - Authenticated Stored XSS Download Manager Free and Pro is prone to an authenticated stored XSS that allows an attacker to create new download package and upload files, called <svg onload=alert(0)>.jpg. This vulnerability works, when user try to edit this download package. Upgrade to the latest version.
Affected versions
max 2.7.95.
Status
vulnerable

Download Manager # e27ab2277e8017a6079888199a72ae641e378e1e

Application

Download Manager

Date
Dec 20, 2015
Research Description
Download Manager [download-manager] < 2.7.95 WordPress Download Manager Plugin <= 2.7.94 - Stored XSS Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Affected versions
max 2.7.95.
Status
vulnerable

Download Manager # ea7d1ab6444f8a0a8263d0e893247937cbf5f536

Application

Download Manager

Date
May 15, 2015
Research Description
Download Manager [download-manager] < 2.2.3 WordPress Download Manager Plugin <= 2.2.2 - XSS This plugin is prone to admin.php cid parameter cross site scripting vulnerability. Update the plugin.
Affected versions
max 2.2.3.
Status
vulnerable

Download Manager # 64e4c85301ceb67932089f2b99f60f1b13e950bf

Application

Download Manager

Date
Apr 23, 2019
Research Description
Download Manager [download-manager] < 2.9.94 WordPress Download Manager plugin <= 2.9.93 - Authenticated Cross-Site Scripting (XSS) vulnerability Authenticated Cross-Site Scripting (XSS) vulnerability found by MgThuraMoeMyint on WordPress Download Manager plugin (versions <= 2.9.93).
Affected versions
max 2.9.94.
Status
vulnerable

Download Manager # 2dbefbf8b0b9f63fcb15ce856bdbeb59159cb13d

Application

Download Manager

Date
Dec 15, 2014
Research Description
Download Manager [download-manager] >= 2.7.0 - <= 2.7.4 WordPress Download Manager 2.7.4 - Remote Code Execution Download Manager plugin is prone to a remote code execution vulnerability via "/download-manager/wpdm-core.php". It allows attackers to execute arbitrary PHP code. Upgrade the plugin.
Affected versions
Min 2.7.0, max 2.7.4.
Status
vulnerable

Download Manager # 95deb79c-bf19-4ab5-aac6-702a13323356

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.2.44 Download Manager &lt; 3.2.44 - Unauthenticated Reflected Cross-Site Scripting The plugin does not escape a generated URL before outputting it back in an attribute of the login page made by the plugin, leading to Reflected Cross-Site Scripting, which is only exploitable against unauthenticated users
Affected versions
max 3.2.44.
Status
vulnerable

Download Manager # c6db3508368504fe0f4a857a752127f0b8bca795

Application

Download Manager

Date
Jun 27, 2022
Research Description
Download Manager [download-manager] < 3.2.44 WordPress Download Manager plugin <= 3.2.43 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Download Manager plugin (versions <= 3.2.43). Update the WordPress Download Manager plugin to the latest available version (at least 3.2.44).
Affected versions
max 3.2.44.
Status
vulnerable

Download Manager # bc88aa10-b861-4426-8bcd-ab1b4a2214ab

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.1.23 Download Manager &lt; 3.1.23 - Unauthorised Asset Manager Usage The majority of the AJAX actions related to the Asset Manager use the same nonce action (ie the NONCE_KEY constant), and are lacking any authorisation checks. Given that the nonce is available in other pages, accessible by low priviledge users (such as author, or even subscribers depending on the plugin&#039;s feature used), this could lead to unauthorised use of the Asset Manager. Exploitation of the mkDir, newFile, scanDir, createZip, unZip, deleteItem, openFile, fileSettings, saveFile, moveItem, copyItem would be quite difficult to achieve, as their file/path parameters are encrypted using SECURE_AUTH_KEY or NONCE_SALT, nonetheless, they should be properly secured. However, the addComment, addShareLink, getLinkDet, updateLink, deleteLink and renameItem can be exploited.
Affected versions
max 3.1.23.
Status
vulnerable

Download Manager # 394007c5-7923-46fe-bb4c-2377d66ff900

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.2.53 Download Manager &lt; 3.2.53 - Unauthenticated Reflected Cross-Site Scripting The plugin does not escape the $_SERVER[&#039;REQUEST_URI&#039;] parameter before outputting it back in an attribute of the modal login page (only available when users are not logged in), which could lead to Reflected Cross-Site Scripting in old web browsers.
Affected versions
max 3.2.53.
Status
vulnerable

Download Manager # 115a6fd3-a723-4167-a9a3-379871f13fcb

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.2.13 WordPress Download Manager &lt; 3.2.13 - Email Template Setting Update via CSRF The plugin did not have CSRF check in place before saving its Email Template setting, allowing attackers to make a logged in admin change them via a CSRF attack
Affected versions
max 3.2.13.
Status
vulnerable

Download Manager # 4ca9f811-3461-4dea-938f-1528440e2708

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.1.19 Download Manager &lt; 3.1.19 - Authenticated (author+) PHP4 File Upload to RCE The wpdm_admin_upload_file AJAX action used a blacklist approach to forbid potential dangerous files, such as PHP, from being uploaded. However, other dangerous extensions, like .php4 were not forbidden.
Affected versions
max 3.1.19.
Status
vulnerable

Download Manager # 2a9331b1-1d43-4729-bb0a-9198ffe3d703

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.1.22 Download Manager &lt; 3.1.22 - Plugin Settings Change via CSRF The wpdm_settings AJAX action, used the section POST parameter to call the associated settings handler methods dynamically. However, the pluginUpdate() (section=plugin-update) and Privacy() (section=privacy) were missing CSRF checks. Furthermore, the Privacy() function did not ensure that the options to be updated were actually related to privacy, allowing any option key containing _wpdm_ to be updated.
Affected versions
max 3.1.22.
Status
vulnerable

Download Manager # b0ac361a-bad1-48f0-9554-3fca6c67054c

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 2.7.5 Download Manager &lt;= 2.7.4 - Code Execution / Remote File Inclusion The WordPress Download Manager WordPress plugin was affected by a Code Execution / Remote File Inclusion security vulnerability.
Affected versions
max 2.7.5.
Status
vulnerable

Download Manager # ee6104ce-7e85-4bfc-9753-56d942e750ef

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 2.9.97 Download Manager &lt;= 2.9.96 - Various Sanitisation Issues The WordPress Download Manager WordPress plugin was affected by a Various Sanitisation Issues security vulnerability.
Affected versions
max 2.9.97.
Status
vulnerable

Download Manager # ef20a37f-b2c2-4857-9267-1d5d17166b77

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 2.9.61 Download Manager &lt;= 2.9.60 - Cross-Site Request Forgery (CSRF) The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
Affected versions
max 2.9.61.
Status
vulnerable

Download Manager # 475bb8d46bd97d6fc2a097080b3f99a444f3d59d

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.2.60 WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS) Update the WordPress Download Manager plugin to the latest available version (at least 3.2.60). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.60.
Affected versions
max 3.2.60.
Status
vulnerable

Download Manager # 28dc54841f3431e6c1ae619323673953e6c9ad07

Application

Download Manager

Date
Jun 23, 2022
Research Description
Download Manager [download-manager] < 3.2.44 Download Manager <= 3.2.43 - Reflected Cross-Site Scripting The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 3.2.44.
Status
vulnerable

Download Manager # 4f1196b4-807f-4238-8cfa-82046f786cb4

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 2.9.46 Download Manager &lt;= 2.9.45 - Cross-Site Request Forgery (CSRF) The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
Affected versions
max 2.9.46.
Status
vulnerable

Download Manager # f0882d39ee4fe7bd5f3cbc58ec5a01067f2336a9

Application

Download Manager

Date
Aug 04, 2022
Research Description
Download Manager [download-manager] < 3.2.54 Download Manager <= 3.2.53 - Reflected Cross-Site Scripting The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 3.2.54.
Status
vulnerable

Download Manager # d4451caae529c7afd19fe3b86e0b1e84960afd50

Application

Download Manager

Date
Aug 09, 2021
Research Description
Download Manager [download-manager] < 3.2.13 WordPress Download Manager <= 3.2.12 - Cross-Site Request Forgery The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for unauthenticated attackers to save the plugins email settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.2.13.
Status
vulnerable

Download Manager # 9f865ea2da941668d15a46e0d2f58ce77f2047df

Application

Download Manager

Date
Apr 30, 2021
Research Description
Download Manager [download-manager] < 3.1.22 WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.1.22.
Status
vulnerable

Download Manager # 95facb10-514c-45dc-a164-7aa54741513b

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 3.1.18 WordPress Download Manager &lt; 3.1.18 - Unauthorised Download Duplication The duplicate() method, hooked to the admin_init action did not have any CSRF and authorisation checks, allowing unauthorised users (such as unauthenticated ones) to duplicate arbitrary downloads
Affected versions
max 3.1.18.
Status
vulnerable

Download Manager # ea09b240-6add-4278-9a15-5b9e356ebd3c

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 2.8.8 Download Manager &lt;= 2.8.7 - Multiple Vulnerabilities Numerous vulnerabilities with WordPress Download Manager free and pro versions. Privilege escalation, directory listing and unauthorised file download.
Affected versions
max 2.8.8.
Status
vulnerable

Download Manager # 2d592bc0-5ab8-43ba-927e-32f8323630bf

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 2.7.95 Download Manager &lt;= 2.7.94 - Authenticated Stored XSS The stored XSS vulnerability allows any authenticated user to inject malicious code via the name of the uploaded file: Example: &lt;svg onload=alert(0)&gt;.jpg The vulnerability exists because the file name is not properly sanitized and this can lead to malicious code injection that will be executed on the target&rsquo;s browser.
Affected versions
max 2.7.95.
Status
vulnerable

Download Manager # ec0c6d34-515c-4d6b-8ee0-af0f45b9705a

Application

Download Manager

Date
-
Research Description
Download Manager [download-manager] < 2.2.3 Download Manager &lt;= 2.2.2 - admin.php cid Parameter XSS The WordPress Download Manager WordPress plugin was affected by an admin.php cid Parameter XSS security vulnerability.
Affected versions
max 2.2.3.
Status
vulnerable

Download Manager # 1cc47941b582e70eb3c7a084fea122889f7c8f61

Application

Download Manager

Date
Apr 30, 2021
Research Description
Download Manager [download-manager] < 3.1.23 WordPress Download Manager < 3.1.23 - Arbitrary Asset Manager Usage The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers with low level privileges to reveal the nonce in pages available to them and use it to perform unauthorized actions.
Affected versions
max 3.1.23.
Status
vulnerable

Download Manager # 08495341a9e6640a1aacf0b99715dcfd0953bd70

Application

Download Manager

Date
Aug 01, 2014
Research Description
Download Manager [download-manager] < 2.2.3 Download Manager <= 2.2.2 - Cross-Site Scripting The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.2.3.
Status
vulnerable

Download Manager # 31742cfb2965f38502dac33371b153129846889a

Application

Download Manager

Date
Jan 19, 2016
Research Description
Download Manager [download-manager] < 2.8.8 Download Manager <= 2.8.7 - Privilege Escalation The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.
Affected versions
max 2.8.8.
Status
vulnerable

Download Manager # a2169e8d1c00cb0652611da65e6d3eed775cc5c0

Application

Download Manager

Date
Jul 16, 2015
Research Description
Download Manager [download-manager] < 2.7.95 WordPress Download Manager <= 2.7.94 - Stored Cross-Site Scripting The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.7.95.
Status
vulnerable

Download Manager # 413f54781ffb5ef3531adbeaaf6527a75a4cd160

Application

Download Manager

Date
Apr 30, 2021
Research Description
Download Manager [download-manager] < 3.1.19 WordPress Download Manager < 3.1.19 - Arbitrary File Upload The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level privileges and above to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected versions
max 3.1.19.
Status
vulnerable

Download Manager # 8bf7dc0b13ac87ac6d84b97aa69a69fa26e9a8c5

Application

Download Manager

Date
Mar 01, 2017
Research Description
Download Manager [download-manager] < 2.9.46 WordPress Download Manager <= 2.9.45 - Cross-Site Request Forgery The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it possible for unauthenticated attackers to modify administrative settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.9.46.
Status
vulnerable

Download Manager # e4733db3755ac8693f863fc176843c66bf34b8e3

Application

Download Manager

Date
Jan 19, 2016
Research Description
Download Manager [download-manager] < 2.8.8 Download Manager <= 2.8.7 - Missing Authorization The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary files with posts and subsequently download those files causing sensitive information disclosure.
Affected versions
max 2.8.8.
Status
vulnerable

Download Manager # f3f46b154001f285c6e191f079b8effcaa304bac

Application

Download Manager

Date
Dec 07, 2013
Research Description
Download Manager [download-manager] < 2.5.9 Download Manager <= 2.5.8 - Cross-Site Scripting The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.5.9.
Status
vulnerable

Download Manager # c7624b475fdc9965e4feb7e8aeb5f8eedf454fcc

Application

Download Manager

Date
Jan 09, 2018
Research Description
Download Manager [download-manager] < 2.9.61 WordPress Download Manager <= 2.9.6 - Cross-Site Request Forgery The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for unauthenticated attackers to install malicious plugins and/or packages via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.9.61.
Status
vulnerable

Download Manager # 1409f1212928d045f22001ff52b340f183d13670

Application

Download Manager

Date
Jan 19, 2016
Research Description
Download Manager [download-manager] < 2.8.8 Download Manager <= 2.8.7 - Sensitive Information Disclosure via Directory Listing The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers to read all of the files listed in that directory.
Affected versions
max 2.8.8.
Status
vulnerable

Download Manager # 6a91e3f815451e2e78fe37ca7dd66491b9289998

Application

Download Manager

Date
Dec 15, 2014
Research Description
Download Manager [download-manager] < 2.7.5 WordPress Download Manager <= 2.7.4 - Remote Code Execution The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.
Affected versions
max 2.7.5.
Status
vulnerable

Download Manager # bf80a7f6a2d48f38eeb6ada67189ba397eff748a

Application

Download Manager

Date
Apr 16, 2021
Research Description
Download Manager [download-manager] < 3.1.17 Download Manager <= 3.1.17 - Missing Authorization The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable sites downloads.
Affected versions
max 3.1.17.
Status
vulnerable

Download Manager # 6d7fd8a034d7b0b580fc963fd2ce56fd672504f4

Application

Download Manager

Date
Jun 16, 2019
Research Description
Download Manager [download-manager] < 2.9.97 WordPress Download Manager <= 2.9.96 - Cross-Site Scripting The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.9.97.
Status
vulnerable