📦 Download Manager

by W3eden

🔍 What is Download Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-1809

HIGH CVSS 7.5 May 2, 2023

The Download Manager WordPress plugin before version 6.3.0 exposes master key information without authentication, allowing attackers to bypass password protection and download any password-protected f...

CVE-2022-45836

HIGH CVSS 7.1 Apr 18, 2023

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the Download Manager plugin. When users click specially crafted links, the scripts execute in...

CVE-2022-0828

HIGH CVSS 7.5 Apr 11, 2022

This vulnerability in the Download Manager WordPress plugin allows attackers to brute-force download access keys, bypassing role-based restrictions and password protections. Any WordPress site using a...

CVE-2021-25087

HIGH CVSS 7.5 Mar 7, 2022

The Download Manager WordPress plugin before version 3.2.35 has REST API endpoints without proper authorization checks, allowing unauthenticated attackers to access sensitive information. This affects...

CVE-2021-34639

HIGH CVSS 7.5 Aug 5, 2021

This vulnerability allows authenticated WordPress users with Author+ permissions to upload files with double extensions (like 'payload.php.png') that may execute as PHP code depending on server config...

CVE-2025-4367

MEDIUM CVSS 6.4 Jun 19, 2025

The Download Manager WordPress plugin has a stored XSS vulnerability in all versions up to 3.3.18. Authenticated attackers with author-level access or higher can inject malicious scripts via the wpdm_...

CVE-2025-1785

MEDIUM CVSS 5.4 Mar 13, 2025

The Download Manager plugin for WordPress has a directory traversal vulnerability that allows authenticated attackers with Author-level permissions or higher to overwrite certain file types outside in...

CVE-2024-10706

MEDIUM CVSS 4.8 Dec 20, 2024

This vulnerability allows high-privilege WordPress users (like administrators) to inject malicious scripts into plugin settings, which then execute when other users view those settings. It affects Wor...

CVE-2024-11768

MEDIUM CVSS 5.3 Dec 19, 2024

The Download Manager WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to download password-protected files without valid credentials. This affects all ...

CVE-2024-8444

MEDIUM CVSS 5.4 Oct 30, 2024

This vulnerability in the Download Manager WordPress plugin allows attackers to inject malicious scripts via unsanitized shortcode parameters. When exploited, it enables cross-site scripting attacks t...

CVE-2024-6208

MEDIUM CVSS 6.4 Jul 31, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Download Manager plugin's 'wpdm_all_packages' shortcode...

CVE-2024-5266

MEDIUM CVSS 6.4 Jun 12, 2024

The Download Manager Pro WordPress plugin has a stored XSS vulnerability in multiple shortcodes that allows authenticated attackers with contributor access or higher to inject malicious scripts. These...

CVE-2024-4160

MEDIUM CVSS 6.4 May 31, 2024

This stored XSS vulnerability in WordPress Download Manager plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts into website pages. When users vis...

CVE-2024-32131

MEDIUM CVSS 5.3 May 17, 2024

This vulnerability in the WordPress Download Manager plugin allows attackers to bypass password protection on files, exposing sensitive information to unauthorized users. It affects all WordPress site...