Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Download Manager MEDIUM 5.4
CVE-2025-4367

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions…

Fix: 3.3.19+
Fix from $1,600 2025-06-19
Download Manager HIGH 8.1
CVE-2025-1785

The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' ac…

Fix: 3.3.09+
Fix from $1,950 2025-03-13
Download Manager MEDIUM 6.3
CVE-2024-56217

Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Le…

Fix: 3.3.04+
Fix from $1,600 2024-12-31
Download Manager MEDIUM 5.3
CVE-2024-11768

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on…

Fix: 3.3.04+
Fix from $1,600 2024-12-19
Download Manager HIGH 7.3
CVE-2024-11740

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is du…

Fix: 3.3.04+
Fix from $1,950 2024-12-19
Download Manager MEDIUM 5.4
CVE-2024-8444

The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.

Fix: 3.3.00+
Fix from $1,600 2024-10-30
Download Manager MEDIUM 5.4
CVE-2024-6208

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions…

Fix: 3.2.98+
Fix from $1,600 2024-07-31
Download Manager HIGH 7.5
CVE-2024-2098

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLib…

Fix: 3.2.90+
Fix from $1,950 2024-06-13
Download Manager MEDIUM 5.4
CVE-2024-1766

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including…

Fix: 3.2.87+
Fix from $1,600 2024-06-12
Download Manager MEDIUM 5.4
CVE-2024-5266

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm…

Fix: 3.2.94+
Fix from $1,600 2024-06-12
Download Manager MEDIUM 5.4
CVE-2024-4160

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions…

Fix: 3.2.90+
Fix from $1,600 2024-05-31
Download Manager HIGH 7.5
CVE-2024-32131

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affe…

Fix: 3.2.83+
Fix from $1,950 2024-05-17
Download Manager MEDIUM 5.4
CVE-2024-29114

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XS…

Fix: 3.2.85+
Fix from $1,600 2024-03-19
Download Manager MEDIUM 5.4
CVE-2023-6954

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and i…

Fix: after 3.2.85
Fix from $1,600 2024-03-13
Download Manager MEDIUM 5.3
CVE-2023-6785

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and includ…

Fix: 3.2.85+
Fix from $1,600 2024-03-13
Download Manager HIGH 7.5
CVE-2023-6421

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

Fix: 3.2.83+
Fix from $1,950 2024-01-01
Download Manager MEDIUM 5.4
CVE-2023-2305

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' sho…

Fix: 3.2.71+
Fix from $1,600 2023-06-09
Download Manager MEDIUM 6.5
CVE-2023-1524

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master ke…

Fix: 3.2.71+
Fix from $1,600 2023-05-30
Download Manager HIGH 7.5
CVE-2023-1809

The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbit…

Fix: 6.3.0+
Fix from $1,950 2023-05-02
Download Manager MEDIUM 6.1
CVE-2022-45836

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

Fix: 3.2.60+
Fix from $1,600 2023-04-18
Download Manager MEDIUM 5.4
CVE-2022-4476

The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the…

Fix: 3.2.62+
Fix from $1,600 2023-01-16
Download Manager HIGH 8.8
CVE-2022-2431

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficie…

Fix: after 3.2.50
Fix from $1,950 2022-09-06
Download Manager HIGH 8.8
CVE-2022-2436

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to…

Fix: 3.2.50+
Fix from $1,950 2022-09-06
Download Manager HIGH 8.8
CVE-2022-36288

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Fix: after 3.2.48
Fix from $1,950 2022-08-23
Download Manager MEDIUM 5.4
CVE-2022-34658

Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Fix: after 3.2.48
Fix from $1,600 2022-08-23
Download Manager HIGH 8.8
CVE-2022-34347

Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

Fix: after 3.2.48
Fix from $1,950 2022-08-22
Download Manager HIGH 7.5
CVE-2022-2362

The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes …

Fix: 3.2.50+
Fix from $1,950 2022-08-22
Download Manager MEDIUM 5.4
CVE-2022-2101

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and inclu…

Fix: after 3.2.46
Fix from $1,600 2022-07-18
Download Manager MEDIUM 6.1
CVE-2022-2168

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboar…

Fix: 3.2.44+
Fix from $1,600 2022-07-17
Download Manager MEDIUM 6.1
CVE-2022-1985

The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to ins…

Fix: after 3.2.42
Fix from $1,600 2022-06-13