Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesDownload Manager

Download Manager vulnerabilities

Download Manager has 63 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.

Known vulnerabilities
63
Active installs
100,000+
Latest version
3.3.71
Last updated
27 Sep 2026
Most recent
2 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-94405
Medium 5.3Up to 3.3.71No fixed version yet5 d ago
Cross-site scripting (XSS)
CVE-2026-97338
Medium 6.4Up to 3.3.70Fixed in a later version (latest 3.3.71)5 d ago
Cross-site scripting (XSS)
CVE-2026-86610
Medium 6.4Before 3.3.71Fixed in 3.3.716 d ago
Cross-site scripting (XSS)
CVE-2026-86609
High 8.8Before 7.5.6Fixed in 7.5.610 d ago
Broken access control
CVE-2026-92714
Medium 6.5Up to 3.3.68Fixed in a later version (latest 3.3.71)18 Sep 2026
Cross-site scripting (XSS)
CVE-2026-16685
Medium 6.4Up to 3.3.66Fixed in a later version (latest 3.3.71)1 Aug 2026
Cross-site scripting (XSS)
CVE-2026-14292
Medium 5.4Before 3.3.66Fixed in 3.3.661 Aug 2026
Broken access control
CVE-2026-14235
High 7.5Before 3.3.62Fixed in 3.3.6227 Jul 2026
Cross-site scripting (XSS)
CVE-2026-14343
Medium 6.4Up to 3.3.61Fixed in a later version (latest 3.3.71)9 Jul 2026
Cross-site scripting (XSS)
CVE-2026-13733
Medium 6.4Up to 3.3.60Fixed in a later version (latest 3.3.71)1 Jul 2026
Broken access control
CVE-2026-4057
Medium 4.3Up to 3.3.51Fixed in a later version (latest 3.3.71)10 Apr 2026
Cross-site scripting (XSS)
CVE-2026-5357
Medium 6.4Up to 3.3.52Fixed in a later version (latest 3.3.71)9 Apr 2026
Broken access control
CVE-2026-2571
Medium 4.3Up to 3.3.49Fixed in a later version (latest 3.3.71)19 Mar 2026
Cross-site scripting (XSS)
CVE-2026-1666
Medium 6.1Up to 3.3.46Fixed in a later version (latest 3.3.71)18 Feb 2026
Privilege escalation
CVE-2025-15364
High 7.3Up to 3.3.40Fixed in a later version (latest 3.3.71)6 Jan 2026
Broken access control
CVE-2025-13498
Medium 4.3Up to 3.3.32Fixed in a later version (latest 3.3.71)18 Dec 2025
Broken access control
CVE-2025-12177
Medium 5.3Up to 3.3.30Fixed in a later version (latest 3.3.71)8 Nov 2025
Cross-site scripting (XSS)
CVE-2025-10146
Medium 6.1Up to 3.3.23Fixed in a later version (latest 3.3.71)19 Sep 2025
Cross-site scripting (XSS)
CVE-2025-4367
Medium 6.4Before 3.3.19Fixed in 3.3.1919 Jun 2025
Cross-site scripting (XSS)
CVE-2024-8284
Medium 4.8Before 3.2.99Fixed in 3.2.9915 May 2025
Remote code execution
CVE-2025-3404
High 8.8Up to 3.3.12Fixed in a later version (latest 3.3.71)19 Apr 2025
Cross-site scripting (XSS)
CVE-2025-3056
Medium 5.4Up to 3.3.12Fixed in a later version (latest 3.3.71)18 Apr 2025
Broken access control
CVE-2024-13126
Medium 4.6Before 3.3.07Fixed in 3.3.0716 Mar 2025
Path traversal
CVE-2025-1785
Medium 5.4Before 3.3.09Fixed in 3.3.0913 Mar 2025
Cross-site scripting (XSS)
CVE-2024-10706
Medium 4.8Before 3.3.03Fixed in 3.3.0320 Dec 2024
Broken access control
CVE-2024-11768
Medium 5.3Before 3.3.04Fixed in 3.3.0419 Dec 2024
Remote code execution
CVE-2024-11740
High 7.3Before 3.3.04Fixed in 3.3.0419 Dec 2024
Cross-site scripting (XSS)
CVE-2024-8444
Medium 5.4Before 3.3.00Fixed in 3.3.0030 Oct 2024
Cross-site scripting (XSS)
CVE-2024-6208
Medium 6.4Before 3.2.98Fixed in 3.2.9831 Jul 2024
Broken access control
CVE-2024-2098
High 7.5Before 3.2.90Fixed in 3.2.9013 Jun 2024
Cross-site scripting (XSS)
CVE-2024-1766
Medium 4.4Before 3.2.87Fixed in 3.2.8712 Jun 2024
Cross-site scripting (XSS)
CVE-2024-5266
Medium 6.4Before 3.2.94Fixed in 3.2.9412 Jun 2024
Cross-site scripting (XSS)
CVE-2024-4001
Medium 6.4Before 3.2.94Fixed in 3.2.945 Jun 2024
Cross-site scripting (XSS)
CVE-2024-4160
Medium 6.4Before 3.2.90Fixed in 3.2.9031 May 2024
Cross-site scripting (XSS)
CVE-2023-6954
Medium 6.4Up to 3.2.85Fixed in a later version (latest 3.3.71)13 Mar 2024
Broken access control
CVE-2023-6785
Medium 5.3Before 3.2.85Fixed in 3.2.8513 Mar 2024
Security weakness
CVE-2023-6421
High 7.5Before 3.2.83Fixed in 3.2.831 Jan 2024
Cross-site scripting (XSS)
CVE-2023-2305
Medium 6.4Before 3.2.71Fixed in 3.2.719 Jun 2023
Security weakness
CVE-2023-1524
Medium 6.5Before 3.2.71Fixed in 3.2.7130 May 2023
Security weakness
CVE-2023-1809
High 7.5Before 6.3.0Fixed in 6.3.02 May 2023
Cross-site scripting (XSS)
CVE-2022-4476
Medium 5.4Before 3.2.62Fixed in 3.2.6216 Jan 2023
Path traversal
CVE-2022-2926
Medium 4.9Before 3.2.55Fixed in 3.2.5526 Sep 2022
Remote code execution
CVE-2022-2431
High 8.1Up to 3.2.50Fixed in a later version (latest 3.3.71)6 Sep 2022
PHP object injection
CVE-2022-2436
High 8.8Before 3.2.50Fixed in 3.2.506 Sep 2022
Cross-site request forgery (CSRF)
CVE-2022-36288
Medium 5.4Up to 3.2.48Fixed in a later version (latest 3.3.71)23 Aug 2022
Cross-site scripting (XSS)
CVE-2022-34658
Medium 5.4Up to 3.2.48Fixed in a later version (latest 3.3.71)23 Aug 2022
Cross-site request forgery (CSRF)
CVE-2022-34347
Medium 4.2Up to 3.2.48Fixed in a later version (latest 3.3.71)22 Aug 2022
Cross-site scripting (XSS)
CVE-2022-2362
High 7.5Before 3.2.50Fixed in 3.2.5022 Aug 2022
Cross-site scripting (XSS)
CVE-2022-2101
Medium 6.4Up to 3.2.46Fixed in a later version (latest 3.3.71)18 Jul 2022
Cross-site scripting (XSS)
CVE-2022-2168
Medium 6.1Before 3.2.44Fixed in 3.2.4417 Jul 2022
Cross-site scripting (XSS)
CVE-2022-1985
Medium 6.1Up to 3.2.42Fixed in a later version (latest 3.3.71)13 Jun 2022
Security weakness
CVE-2022-0828
High 7.5Before 3.2.34Fixed in 3.2.3411 Apr 2022
Sensitive data exposure
CVE-2021-25087
High 7.5Before 3.2.35Fixed in 3.2.357 Mar 2022
Cross-site scripting (XSS)
CVE-2021-25069
High 8.8Before 3.2.34Fixed in 3.2.3421 Feb 2022
Cross-site scripting (XSS)
CVE-2021-24969
Medium 5.4Before 3.2.22Fixed in 3.2.2227 Dec 2021
Cross-site scripting (XSS)
CVE-2021-24773
Medium 4.8Before 3.2.16Fixed in 3.2.161 Nov 2021
Cross-site scripting (XSS)
CVE-2021-34638
Medium 6.5Up to 3.1.24Fixed in a later version (latest 3.3.71)5 Aug 2021
Security weakness
CVE-2021-34639
High 7.5Up to 3.1.24Fixed in a later version (latest 3.3.71)5 Aug 2021
Cross-site scripting (XSS)
CVE-2019-15889
Medium 6.1Before 2.9.94Fixed in 2.9.943 Sep 2019
Cross-site scripting (XSS)
CVE-2017-18032
Medium 6.1Before 2.9.52Fixed in 2.9.5216 Jan 2018
Cross-site scripting (XSS)
CVE-2017-2216
Medium 6.1Up to 2.9.49Fixed in a later version (latest 3.3.71)7 Jul 2017
Open redirect
CVE-2017-2217
Medium 6.1Up to 2.9.50Fixed in a later version (latest 3.3.71)7 Jul 2017
Cross-site scripting (XSS)
CVE-2013-7319
Not scoredUp to 2.5.8Fixed in a later version (latest 3.3.71)6 Feb 2014
Read the published descriptions
CVE-2026-94405, 2 Oct 2026
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. CVE record
CVE-2026-97338, 2 Oct 2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization. CVE record
CVE-2026-86610, 1 Oct 2026
The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue, including administrators. Only sites running PHP below 8.1 are affected, as the sanitisation applied when the setting is saved does not neutralise single quotes there. CVE record
CVE-2026-86609, 27 Sep 2026
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature. CVE record
CVE-2026-92714, 18 Sep 2026
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata - including protected file references, role-based access restrictions, and password lock settings - into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files. CVE record
CVE-2026-16685, 1 Aug 2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post() does not neutralize the payload because it operates on post content at save time and does not process shortcode attribute values that are emitted unescaped at render time. CVE record
CVE-2026-14292, 1 Aug 2026
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package. CVE record
CVE-2026-14235, 27 Jul 2026
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization. CVE record
CVE-2026-14343, 9 Jul 2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode. CVE record
CVE-2026-13733, 1 Jul 2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although wp_kses_post is applied to post content on save, it only strips HTML tokens and does not neutralize C-style escape sequences embedded within shortcode attribute values, meaning contributors can craft a payload that survives the kses filter and is silently reconstructed into a raw script tag at render time. CVE record
CVE-2026-4057, 10 Apr 2026
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verifying post ownership via `current_user_can('edit_post', $id)`, and the destructive operations executing before the admin-level check in `mediaAccessControl()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to strip all protection metadata (password, access restrictions, private flag) from any media file they do not own, making admin-protected files publicly accessible via their direct URL. CVE record
CVE-2026-5357, 9 Apr 2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is extracted without sanitization in the members() function and stored via update_post_meta(), then echoed directly into an HTML id attribute in the members.php template without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page. CVE record
CVE-2026-2571, 19 Mar 2026
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates. CVE record
CVE-2026-1666, 18 Feb 2026
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2025-15364, 6 Jan 2026
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account. CVE record
CVE-2025-13498, 18 Dec 2025
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files. CVE record
CVE-2025-12177, 8 Nov 2025
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache. CVE record
CVE-2025-10146, 19 Sep 2025
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2025-4367, 19 Jun 2025
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-8284, 15 May 2025
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed CVE record
CVE-2025-3404, 19 Apr 2025
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). CVE record
CVE-2025-3056, 18 Apr 2025
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CVE record
CVE-2024-13126, 16 Mar 2025
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files. CVE record
CVE-2025-1785, 13 Mar 2025
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service. CVE record
CVE-2024-10706, 20 Dec 2024
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-11768, 19 Dec 2024
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files. CVE record
CVE-2024-11740, 19 Dec 2024
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. CVE record
CVE-2024-8444, 30 Oct 2024
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting. CVE record
CVE-2024-6208, 31 Jul 2024
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2098, 13 Jun 2024
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files. CVE record
CVE-2024-1766, 12 Jun 2024
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution. CVE record
CVE-2024-5266, 12 Jun 2024
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4001, 5 Jun 2024
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4160, 31 May 2024
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-6954, 13 Mar 2024
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-6785, 13 Mar 2024
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published). CVE record
CVE-2023-6421, 1 Jan 2024
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. CVE record
CVE-2023-2305, 9 Jun 2023
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-1524, 30 May 2023
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password. CVE record
CVE-2023-1809, 2 May 2023
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files. CVE record
CVE-2022-4476, 16 Jan 2023
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. CVE record
CVE-2022-2926, 26 Sep 2022
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory CVE record
CVE-2022-2431, 6 Sep 2022
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the /wp-config.php file which will reset the installation and make it possible for an attacker to achieve remote code execution on the server. CVE record
CVE-2022-2436, 6 Sep 2022
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload. CVE record
CVE-2022-36288, 23 Aug 2022
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. CVE record
CVE-2022-34658, 23 Aug 2022
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. CVE record
CVE-2022-34347, 22 Aug 2022
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. CVE record
CVE-2022-2362, 22 Aug 2022
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions. CVE record
CVE-2022-2101, 18 Jul 2022
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page. CVE record
CVE-2022-2168, 17 Jul 2022
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting CVE record
CVE-2022-1985, 13 Jun 2022
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file. CVE record
CVE-2022-0828, 11 Apr 2022
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download. CVE record
CVE-2021-25087, 7 Mar 2022
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25). CVE record
CVE-2021-25069, 21 Feb 2022
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue CVE record
CVE-2021-24969, 27 Dec 2021
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks CVE record
CVE-2021-24773, 1 Nov 2021
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed CVE record
CVE-2021-34638, 5 Aug 2021
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions. CVE record
CVE-2021-34639, 5 Aug 2021
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions. CVE record
CVE-2019-15889, 3 Sep 2019
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter. CVE record
CVE-2017-18032, 16 Jan 2018
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php. CVE record
CVE-2017-2216, 7 Jul 2017
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CVE record
CVE-2017-2217, 7 Jul 2017
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. CVE record
CVE-2013-7319, 6 Feb 2014
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field. CVE record

What to do if you run Download Manager

If you run Download Manager, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Download Manager vulnerabilities

Free. We email you when a new vulnerability is published for Download Manager, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support