Download Manager

Information

Software Type Plugin
Software Slug download-manager (view on wordpress.org)
Software Status Active
Software Author codename065
Software Website www.wpdownloadmanager.com
Software Downloads 11,296,518
Software Active Installs 100,000
Software Record Last Updated July 22, 2026

Showing 1-20 of 79 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes Patched CVE-2026-14343 6.4 PRISM July 8, 2026
Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute Patched CVE-2026-13733 6.4 PRISM June 30, 2026
Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal Patched CVE-2026-4057 4.3 Or Benit April 9, 2026
Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes Patched CVE-2026-5357 6.4 zaim April 8, 2026
Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter Patched CVE-2026-2571 4.3 Quốc Huy (jtwings) March 18, 2026
Download Manager <= 3.3.52 - Missing Authorization Patched CVE-2026-39676 5.3 Steven Julian February 19, 2026
Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter Patched CVE-2026-1666 6.1 Jack Taylor February 17, 2026
Download Manager <= 3.3.53 - Authenticated (Author+) Stored Cross-Site Scripting Patched CVE-2026-39615 6.4 hhhai February 10, 2026
Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword Patched CVE-2025-15364 7.3 Drew Webber (mcdruid) January 5, 2026
Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure Patched CVE-2025-13498 4.3 type5afe December 17, 2025
Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key Patched CVE-2025-12177 5.3 Jack Pas (Dark.) November 7, 2025
Download Manager <= 3.3.32 - Authenticated (Subscriber+) Information Exposure Patched CVE-2025-63070 4.3 Que Thanh Tuan - Blue Rock September 30, 2025
Download Manager <= 3.3.25 - Unauthenticated Sensitive Information Exposure Patched CVE-2025-60092 5.3 Ananda Dhakal September 26, 2025
Download Manager <= 3.3.24 - Cross-Site Request Forgery Patched CVE-2025-60093 4.3 Ananda Dhakal September 26, 2025
Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter Patched CVE-2025-10146 6.1 vgo0 September 18, 2025
Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode Patched CVE-2025-4367 6.4 Brian Sans-Souci (liardom) June 18, 2025
Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion Patched CVE-2025-3404 8.8 Brian Sans-Souci (liardom), the sneaky squirrel April 18, 2025
Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload Patched CVE-2025-3056 5.4 siavashvafshar April 17, 2025
Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite Patched CVE-2025-1785 5.4 zhuxuan wu March 12, 2025
Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory Patched CVE-2024-13126 5.3 Dmitrii Ignatyev January 17, 2025

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation