Vulnerabilities and security researches forsell-downloads sell-downloads
Direction: ascendingJun 06, 2024
Sell Downloads # CVE-2015-9348
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 27, 2019
- Research Description
- The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
- Affected versions
-
max 1.0.2.
- Status
-
vulnerable
Jun 10, 2024
Sell Downloads # CVE-2014-9511
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- The Sell Downloads plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.0.1 via the 'file' parameter. This can allow unauthenticated attackers to extract sensitive data such as settings/configuration files along with other useful information that can be used in future attacks.
- Affected versions
-
max 1.0.1.
- Status
-
vulnerable
Jan 11, 2026
Sell Downloads # CVE-2025-68850
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 05, 2026
- Research Description
- Missing Authorization vulnerability in Codepeople Sell Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sell Downloads: from n/a through 1.1.12.
- Affected versions
-
max 1.1.12.
- Status
-
vulnerable