HomeWordPress vulnerabilitiesDownload Manager
Download Manager vulnerabilities
Download Manager has 63 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.
- Known vulnerabilities
- 63
- Active installs
- 100,000+
- Latest version
- 3.3.71
- Last updated
- 27 Sep 2026
- Most recent
- 2 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-94405 | Medium 5.3 | Up to 3.3.71 | No fixed version yet | 5 d ago |
| Cross-site scripting (XSS) CVE-2026-97338 | Medium 6.4 | Up to 3.3.70 | Fixed in a later version (latest 3.3.71) | 5 d ago |
| Cross-site scripting (XSS) CVE-2026-86610 | Medium 6.4 | Before 3.3.71 | Fixed in 3.3.71 | 6 d ago |
| Cross-site scripting (XSS) CVE-2026-86609 | High 8.8 | Before 7.5.6 | Fixed in 7.5.6 | 10 d ago |
| Broken access control CVE-2026-92714 | Medium 6.5 | Up to 3.3.68 | Fixed in a later version (latest 3.3.71) | 18 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-16685 | Medium 6.4 | Up to 3.3.66 | Fixed in a later version (latest 3.3.71) | 1 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-14292 | Medium 5.4 | Before 3.3.66 | Fixed in 3.3.66 | 1 Aug 2026 |
| Broken access control CVE-2026-14235 | High 7.5 | Before 3.3.62 | Fixed in 3.3.62 | 27 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-14343 | Medium 6.4 | Up to 3.3.61 | Fixed in a later version (latest 3.3.71) | 9 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-13733 | Medium 6.4 | Up to 3.3.60 | Fixed in a later version (latest 3.3.71) | 1 Jul 2026 |
| Broken access control CVE-2026-4057 | Medium 4.3 | Up to 3.3.51 | Fixed in a later version (latest 3.3.71) | 10 Apr 2026 |
| Cross-site scripting (XSS) CVE-2026-5357 | Medium 6.4 | Up to 3.3.52 | Fixed in a later version (latest 3.3.71) | 9 Apr 2026 |
| Broken access control CVE-2026-2571 | Medium 4.3 | Up to 3.3.49 | Fixed in a later version (latest 3.3.71) | 19 Mar 2026 |
| Cross-site scripting (XSS) CVE-2026-1666 | Medium 6.1 | Up to 3.3.46 | Fixed in a later version (latest 3.3.71) | 18 Feb 2026 |
| Privilege escalation CVE-2025-15364 | High 7.3 | Up to 3.3.40 | Fixed in a later version (latest 3.3.71) | 6 Jan 2026 |
| Broken access control CVE-2025-13498 | Medium 4.3 | Up to 3.3.32 | Fixed in a later version (latest 3.3.71) | 18 Dec 2025 |
| Broken access control CVE-2025-12177 | Medium 5.3 | Up to 3.3.30 | Fixed in a later version (latest 3.3.71) | 8 Nov 2025 |
| Cross-site scripting (XSS) CVE-2025-10146 | Medium 6.1 | Up to 3.3.23 | Fixed in a later version (latest 3.3.71) | 19 Sep 2025 |
| Cross-site scripting (XSS) CVE-2025-4367 | Medium 6.4 | Before 3.3.19 | Fixed in 3.3.19 | 19 Jun 2025 |
| Cross-site scripting (XSS) CVE-2024-8284 | Medium 4.8 | Before 3.2.99 | Fixed in 3.2.99 | 15 May 2025 |
| Remote code execution CVE-2025-3404 | High 8.8 | Up to 3.3.12 | Fixed in a later version (latest 3.3.71) | 19 Apr 2025 |
| Cross-site scripting (XSS) CVE-2025-3056 | Medium 5.4 | Up to 3.3.12 | Fixed in a later version (latest 3.3.71) | 18 Apr 2025 |
| Broken access control CVE-2024-13126 | Medium 4.6 | Before 3.3.07 | Fixed in 3.3.07 | 16 Mar 2025 |
| Path traversal CVE-2025-1785 | Medium 5.4 | Before 3.3.09 | Fixed in 3.3.09 | 13 Mar 2025 |
| Cross-site scripting (XSS) CVE-2024-10706 | Medium 4.8 | Before 3.3.03 | Fixed in 3.3.03 | 20 Dec 2024 |
| Broken access control CVE-2024-11768 | Medium 5.3 | Before 3.3.04 | Fixed in 3.3.04 | 19 Dec 2024 |
| Remote code execution CVE-2024-11740 | High 7.3 | Before 3.3.04 | Fixed in 3.3.04 | 19 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-8444 | Medium 5.4 | Before 3.3.00 | Fixed in 3.3.00 | 30 Oct 2024 |
| Cross-site scripting (XSS) CVE-2024-6208 | Medium 6.4 | Before 3.2.98 | Fixed in 3.2.98 | 31 Jul 2024 |
| Broken access control CVE-2024-2098 | High 7.5 | Before 3.2.90 | Fixed in 3.2.90 | 13 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-1766 | Medium 4.4 | Before 3.2.87 | Fixed in 3.2.87 | 12 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-5266 | Medium 6.4 | Before 3.2.94 | Fixed in 3.2.94 | 12 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-4001 | Medium 6.4 | Before 3.2.94 | Fixed in 3.2.94 | 5 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-4160 | Medium 6.4 | Before 3.2.90 | Fixed in 3.2.90 | 31 May 2024 |
| Cross-site scripting (XSS) CVE-2023-6954 | Medium 6.4 | Up to 3.2.85 | Fixed in a later version (latest 3.3.71) | 13 Mar 2024 |
| Broken access control CVE-2023-6785 | Medium 5.3 | Before 3.2.85 | Fixed in 3.2.85 | 13 Mar 2024 |
| Security weakness CVE-2023-6421 | High 7.5 | Before 3.2.83 | Fixed in 3.2.83 | 1 Jan 2024 |
| Cross-site scripting (XSS) CVE-2023-2305 | Medium 6.4 | Before 3.2.71 | Fixed in 3.2.71 | 9 Jun 2023 |
| Security weakness CVE-2023-1524 | Medium 6.5 | Before 3.2.71 | Fixed in 3.2.71 | 30 May 2023 |
| Security weakness CVE-2023-1809 | High 7.5 | Before 6.3.0 | Fixed in 6.3.0 | 2 May 2023 |
| Cross-site scripting (XSS) CVE-2022-4476 | Medium 5.4 | Before 3.2.62 | Fixed in 3.2.62 | 16 Jan 2023 |
| Path traversal CVE-2022-2926 | Medium 4.9 | Before 3.2.55 | Fixed in 3.2.55 | 26 Sep 2022 |
| Remote code execution CVE-2022-2431 | High 8.1 | Up to 3.2.50 | Fixed in a later version (latest 3.3.71) | 6 Sep 2022 |
| PHP object injection CVE-2022-2436 | High 8.8 | Before 3.2.50 | Fixed in 3.2.50 | 6 Sep 2022 |
| Cross-site request forgery (CSRF) CVE-2022-36288 | Medium 5.4 | Up to 3.2.48 | Fixed in a later version (latest 3.3.71) | 23 Aug 2022 |
| Cross-site scripting (XSS) CVE-2022-34658 | Medium 5.4 | Up to 3.2.48 | Fixed in a later version (latest 3.3.71) | 23 Aug 2022 |
| Cross-site request forgery (CSRF) CVE-2022-34347 | Medium 4.2 | Up to 3.2.48 | Fixed in a later version (latest 3.3.71) | 22 Aug 2022 |
| Cross-site scripting (XSS) CVE-2022-2362 | High 7.5 | Before 3.2.50 | Fixed in 3.2.50 | 22 Aug 2022 |
| Cross-site scripting (XSS) CVE-2022-2101 | Medium 6.4 | Up to 3.2.46 | Fixed in a later version (latest 3.3.71) | 18 Jul 2022 |
| Cross-site scripting (XSS) CVE-2022-2168 | Medium 6.1 | Before 3.2.44 | Fixed in 3.2.44 | 17 Jul 2022 |
| Cross-site scripting (XSS) CVE-2022-1985 | Medium 6.1 | Up to 3.2.42 | Fixed in a later version (latest 3.3.71) | 13 Jun 2022 |
| Security weakness CVE-2022-0828 | High 7.5 | Before 3.2.34 | Fixed in 3.2.34 | 11 Apr 2022 |
| Sensitive data exposure CVE-2021-25087 | High 7.5 | Before 3.2.35 | Fixed in 3.2.35 | 7 Mar 2022 |
| Cross-site scripting (XSS) CVE-2021-25069 | High 8.8 | Before 3.2.34 | Fixed in 3.2.34 | 21 Feb 2022 |
| Cross-site scripting (XSS) CVE-2021-24969 | Medium 5.4 | Before 3.2.22 | Fixed in 3.2.22 | 27 Dec 2021 |
| Cross-site scripting (XSS) CVE-2021-24773 | Medium 4.8 | Before 3.2.16 | Fixed in 3.2.16 | 1 Nov 2021 |
| Cross-site scripting (XSS) CVE-2021-34638 | Medium 6.5 | Up to 3.1.24 | Fixed in a later version (latest 3.3.71) | 5 Aug 2021 |
| Security weakness CVE-2021-34639 | High 7.5 | Up to 3.1.24 | Fixed in a later version (latest 3.3.71) | 5 Aug 2021 |
| Cross-site scripting (XSS) CVE-2019-15889 | Medium 6.1 | Before 2.9.94 | Fixed in 2.9.94 | 3 Sep 2019 |
| Cross-site scripting (XSS) CVE-2017-18032 | Medium 6.1 | Before 2.9.52 | Fixed in 2.9.52 | 16 Jan 2018 |
| Cross-site scripting (XSS) CVE-2017-2216 | Medium 6.1 | Up to 2.9.49 | Fixed in a later version (latest 3.3.71) | 7 Jul 2017 |
| Open redirect CVE-2017-2217 | Medium 6.1 | Up to 2.9.50 | Fixed in a later version (latest 3.3.71) | 7 Jul 2017 |
| Cross-site scripting (XSS) CVE-2013-7319 | Not scored | Up to 2.5.8 | Fixed in a later version (latest 3.3.71) | 6 Feb 2014 |
Read the published descriptions
- CVE-2026-94405, 2 Oct 2026
- Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. CVE record
- CVE-2026-97338, 2 Oct 2026
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization. CVE record
- CVE-2026-86610, 1 Oct 2026
- The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue, including administrators. Only sites running PHP below 8.1 are affected, as the sanitisation applied when the setting is saved does not neutralise single quotes there. CVE record
- CVE-2026-86609, 27 Sep 2026
- The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature. CVE record
- CVE-2026-92714, 18 Sep 2026
- The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata - including protected file references, role-based access restrictions, and password lock settings - into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files. CVE record
- CVE-2026-16685, 1 Aug 2026
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post() does not neutralize the payload because it operates on post content at save time and does not process shortcode attribute values that are emitted unescaped at render time. CVE record
- CVE-2026-14292, 1 Aug 2026
- The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package. CVE record
- CVE-2026-14235, 27 Jul 2026
- The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization. CVE record
- CVE-2026-14343, 9 Jul 2026
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode. CVE record
- CVE-2026-13733, 1 Jul 2026
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although wp_kses_post is applied to post content on save, it only strips HTML tokens and does not neutralize C-style escape sequences embedded within shortcode attribute values, meaning contributors can craft a payload that survives the kses filter and is silently reconstructed into a raw script tag at render time. CVE record
- CVE-2026-4057, 10 Apr 2026
- The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verifying post ownership via `current_user_can('edit_post', $id)`, and the destructive operations executing before the admin-level check in `mediaAccessControl()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to strip all protection metadata (password, access restrictions, private flag) from any media file they do not own, making admin-protected files publicly accessible via their direct URL. CVE record
- CVE-2026-5357, 9 Apr 2026
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is extracted without sanitization in the members() function and stored via update_post_meta(), then echoed directly into an HTML id attribute in the members.php template without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page. CVE record
- CVE-2026-2571, 19 Mar 2026
- The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates. CVE record
- CVE-2026-1666, 18 Feb 2026
- The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2025-15364, 6 Jan 2026
- The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account. CVE record
- CVE-2025-13498, 18 Dec 2025
- The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files. CVE record
- CVE-2025-12177, 8 Nov 2025
- The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache. CVE record
- CVE-2025-10146, 19 Sep 2025
- The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2025-4367, 19 Jun 2025
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-8284, 15 May 2025
- The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed CVE record
- CVE-2025-3404, 19 Apr 2025
- The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). CVE record
- CVE-2025-3056, 18 Apr 2025
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CVE record
- CVE-2024-13126, 16 Mar 2025
- The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files. CVE record
- CVE-2025-1785, 13 Mar 2025
- The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service. CVE record
- CVE-2024-10706, 20 Dec 2024
- The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-11768, 19 Dec 2024
- The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files. CVE record
- CVE-2024-11740, 19 Dec 2024
- The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. CVE record
- CVE-2024-8444, 30 Oct 2024
- The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting. CVE record
- CVE-2024-6208, 31 Jul 2024
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-2098, 13 Jun 2024
- The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files. CVE record
- CVE-2024-1766, 12 Jun 2024
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution. CVE record
- CVE-2024-5266, 12 Jun 2024
- The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-4001, 5 Jun 2024
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-4160, 31 May 2024
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-6954, 13 Mar 2024
- The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-6785, 13 Mar 2024
- The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published). CVE record
- CVE-2023-6421, 1 Jan 2024
- The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. CVE record
- CVE-2023-2305, 9 Jun 2023
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-1524, 30 May 2023
- The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password. CVE record
- CVE-2023-1809, 2 May 2023
- The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files. CVE record
- CVE-2022-4476, 16 Jan 2023
- The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. CVE record
- CVE-2022-2926, 26 Sep 2022
- The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory CVE record
- CVE-2022-2431, 6 Sep 2022
- The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the /wp-config.php file which will reset the installation and make it possible for an attacker to achieve remote code execution on the server. CVE record
- CVE-2022-2436, 6 Sep 2022
- The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload. CVE record
- CVE-2022-36288, 23 Aug 2022
- Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. CVE record
- CVE-2022-34658, 23 Aug 2022
- Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. CVE record
- CVE-2022-34347, 22 Aug 2022
- Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. CVE record
- CVE-2022-2362, 22 Aug 2022
- The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions. CVE record
- CVE-2022-2101, 18 Jul 2022
- The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page. CVE record
- CVE-2022-2168, 17 Jul 2022
- The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting CVE record
- CVE-2022-1985, 13 Jun 2022
- The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file. CVE record
- CVE-2022-0828, 11 Apr 2022
- The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download. CVE record
- CVE-2021-25087, 7 Mar 2022
- The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25). CVE record
- CVE-2021-25069, 21 Feb 2022
- The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue CVE record
- CVE-2021-24969, 27 Dec 2021
- The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks CVE record
- CVE-2021-24773, 1 Nov 2021
- The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed CVE record
- CVE-2021-34638, 5 Aug 2021
- Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions. CVE record
- CVE-2021-34639, 5 Aug 2021
- Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions. CVE record
- CVE-2019-15889, 3 Sep 2019
- The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter. CVE record
- CVE-2017-18032, 16 Jan 2018
- The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php. CVE record
- CVE-2017-2216, 7 Jul 2017
- Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CVE record
- CVE-2017-2217, 7 Jul 2017
- Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. CVE record
- CVE-2013-7319, 6 Feb 2014
- Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field. CVE record
What to do if you run Download Manager
If you run Download Manager, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Download Manager vulnerabilities
Free. We email you when a new vulnerability is published for Download Manager, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.