Download Manager
download-manager · plugin
Known security vulnerabilities for Download Manager. Find out in seconds which version runs on your site with WP Lens.
49 known vulnerabilities
21 exploitable without logging in · 5 with public exploit code · latest Oct 2, 2026
Listed on wordpress.org · latest 3.3.72 · last updated Oct 2, 2026 · 100K+ installs
wordpress.org status checked on Oct 5, 2026
Vulnerabilities
- High 8.8
CVE-2022-36288unauthenticated · needs a click≤ 3.2.48
WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
- High 8.8
CVE-2022-34347unauthenticated · needs a click≤ 3.2.48
WordPress Download Manager plugin <= 3.2.48 - Cross-Site Request Forgery (CSRF) vulnerability
- High 8.8
CVE-2025-3404author+≤ 3.3.12
Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion
- High 8.8
CVE-2022-2436contributor+≤ 3.2.49
Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization
- High 8.8
CVE-2022-2431contributor+≤ 3.2.50
Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion
- High 8.1
CVE-2025-1785author+≤ 3.3.08
Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite
- High 7.5
CVE-2024-2098unauthenticated≤ 3.2.89
Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary
- High 7.5
CVE-2024-32131unauthenticated≤ 3.2.82
WordPress Download Manager plugin <= 3.2.82 - File Password Lock Bypass vulnerability
- High 7.3
CVE-2025-15364unauthenticated≤ 3.3.40
Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword
- High 7.3
CVE-2024-11740unauthenticated≤ 3.3.03
Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution
- Medium 6.5
CVE-2026-92714contributor+≤ 3.3.68
Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter
- Medium 6.4
CVE-2026-97338subscriber+≤ 3.3.70
Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name
- Medium 6.4
CVE-2026-16685contributor+≤ 3.3.66
Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute
- Medium 6.4
CVE-2026-14343contributor+≤ 3.3.61
Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes
- Medium 6.4
CVE-2026-13733contributor+≤ 3.3.60
Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
- Medium 6.4
CVE-2026-5357contributor+≤ 3.3.52
Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
- Medium 6.3
CVE-2024-56217login required≤ 3.3.03
WordPress Download Manager plugin <= 3.3.03 - Broken Access Control vulnerability
- Medium 6.1
CVE-2026-1666unauthenticated · needs a click≤ 3.3.46
Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter
- Medium 6.1
CVE-2025-10146unauthenticated · needs a click≤ 3.3.23
Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter
- Medium 6.1
CVE-2022-45836unauthenticated · needs a click≤ 3.2.59
WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)
- Medium 6.1
CVE-2022-1985unauthenticated · needs a click≤ 3.2.42
Download Manager <= 3.2.42 - Reflected Cross-Site Scripting
- Medium 6.1
CVE-2019-15889unauthenticated · needs a click
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search
- Medium 6.1
CVE-2017-18032unauthenticated · needs a click
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-aj
- Medium 6.1
CVE-2017-2217unauthenticated · needs a click
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web
- Medium 6.1
CVE-2017-2216unauthenticated · needs a click
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web scr
- Medium 5.9
CVE-2026-39615high privilege≤ 3.3.53
WordPress Download Manager plugin <= 3.3.53 - Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2024-1766subscriber+≤ 3.2.86
Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting
- Medium 5.4
CVE-2024-29114login required≤ 3.2.84
WordPress Download Manager plugin <= 3.2.84 - Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2025-4367author+≤ 3.3.18
Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode
- Medium 5.4
CVE-2025-3056author+≤ 3.3.12
Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
- Medium 5.4
CVE-2024-6208contributor+≤ 3.2.97
Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 5.4
CVE-2024-5266author+≤ 3.2.92
Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes
- Medium 5.4
CVE-2024-4160contributor+≤ 3.2.90
Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode
- Medium 5.4
CVE-2023-6954contributor+≤ 3.2.85
Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 5.4
CVE-2023-2305contributor+≤ 3.2.70
Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 5.4
CVE-2022-34658contributor+≤ 3.2.48
WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
- Medium 5.4
CVE-2022-2101contributor+≤ 3.2.46
Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting
- Medium 5.3
CVE-2026-94405unauthenticated≤ 3.3.71
WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability
- Medium 5.3
CVE-2026-39676unauthenticated≤ 3.3.52
WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability
- Medium 5.3
CVE-2025-12177unauthenticated≤ 3.3.30
Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key
- Medium 5.3
CVE-2025-60092unauthenticated≤ 3.3.25
WordPress Download Manager Plugin <= 3.3.25 - Sensitive Data Exposure Vulnerability
- Medium 5.3
CVE-2024-11768unauthenticated≤ 3.3.03
Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files
- Medium 5.3
CVE-2023-6785unauthenticated≤ 3.2.84
Download Manager <= 3.2.84 - Missing Authorization
- Medium 4.3
CVE-2025-60093unauthenticated · needs a click≤ 3.3.24
WordPress Download Manager Plugin <= 3.3.24 - Cross Site Request Forgery (CSRF) Vulnerability
- Medium 4.3
CVE-2026-2571subscriber+≤ 3.3.49
Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter
- Medium 4.3
CVE-2025-13498subscriber+≤ 3.3.32
Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure
- Medium 4.3
CVE-2025-63070login required≤ 3.3.32
WordPress Download Manager plugin <= 3.3.32 - Sensitive Data Exposure vulnerability
- Medium 4.3
CVE-2026-4057contributor+≤ 3.3.51
Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal
- Medium 4.3
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitra
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).