Skip to content
Noroxi

Download Manager

download-manager · plugin

Known security vulnerabilities for Download Manager. Find out in seconds which version runs on your site with WP Lens.

49 known vulnerabilities

21 exploitable without logging in · 5 with public exploit code · latest Oct 2, 2026

Listed on wordpress.org · latest 3.3.72 · last updated Oct 2, 2026 · 100K+ installs

wordpress.org status checked on Oct 5, 2026

Vulnerabilities

  • CVE-2022-36288unauthenticated · needs a click≤ 3.2.48

    WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities

    High 8.8
  • CVE-2022-34347unauthenticated · needs a click≤ 3.2.48

    WordPress Download Manager plugin <= 3.2.48 - Cross-Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2025-3404author+≤ 3.3.12

    Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion

    High 8.8
  • CVE-2022-2436contributor+≤ 3.2.49

    Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization

    High 8.8
  • CVE-2022-2431contributor+≤ 3.2.50

    Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion

    High 8.8
  • CVE-2025-1785author+≤ 3.3.08

    Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite

    High 8.1
  • CVE-2024-2098unauthenticated≤ 3.2.89

    Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary

    High 7.5
  • CVE-2024-32131unauthenticated≤ 3.2.82

    WordPress Download Manager plugin <= 3.2.82 - File Password Lock Bypass vulnerability

    High 7.5
  • CVE-2025-15364unauthenticated≤ 3.3.40

    Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword

    High 7.3
  • CVE-2024-11740unauthenticated≤ 3.3.03

    Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution

    High 7.3
  • CVE-2026-92714contributor+≤ 3.3.68

    Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter

    Medium 6.5
  • CVE-2026-97338subscriber+≤ 3.3.70

    Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name

    Medium 6.4
  • CVE-2026-16685contributor+≤ 3.3.66

    Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute

    Medium 6.4
  • CVE-2026-14343contributor+≤ 3.3.61

    Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes

    Medium 6.4
  • CVE-2026-13733contributor+≤ 3.3.60

    Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute

    Medium 6.4
  • CVE-2026-5357contributor+≤ 3.3.52

    Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

    Medium 6.4
  • CVE-2024-56217login required≤ 3.3.03

    WordPress Download Manager plugin <= 3.3.03 - Broken Access Control vulnerability

    Medium 6.3
  • CVE-2026-1666unauthenticated · needs a click≤ 3.3.46

    Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter

    Medium 6.1
  • CVE-2025-10146unauthenticated · needs a click≤ 3.3.23

    Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter

    Medium 6.1
  • CVE-2022-45836unauthenticated · needs a click≤ 3.2.59

    WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2022-1985unauthenticated · needs a click≤ 3.2.42

    Download Manager <= 3.2.42 - Reflected Cross-Site Scripting

    Medium 6.1
  • CVE-2019-15889unauthenticated · needs a click

    The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search

    Medium 6.1
  • CVE-2017-18032unauthenticated · needs a click

    The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-aj

    Medium 6.1
  • CVE-2017-2217unauthenticated · needs a click

    Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web

    Medium 6.1
  • CVE-2017-2216unauthenticated · needs a click

    Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web scr

    Medium 6.1
  • CVE-2026-39615high privilege≤ 3.3.53

    WordPress Download Manager plugin <= 3.3.53 - Cross Site Scripting (XSS) vulnerability

    Medium 5.9
  • CVE-2024-1766subscriber+≤ 3.2.86

    Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting

    Medium 5.4
  • CVE-2024-29114login required≤ 3.2.84

    WordPress Download Manager plugin <= 3.2.84 - Cross Site Scripting (XSS) vulnerability

    Medium 5.4
  • CVE-2025-4367author+≤ 3.3.18

    Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode

    Medium 5.4
  • CVE-2025-3056author+≤ 3.3.12

    Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

    Medium 5.4
  • CVE-2024-6208contributor+≤ 3.2.97

    Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2024-5266author+≤ 3.2.92

    Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes

    Medium 5.4
  • CVE-2024-4160contributor+≤ 3.2.90

    Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode

    Medium 5.4
  • CVE-2023-6954contributor+≤ 3.2.85

    Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2023-2305contributor+≤ 3.2.70

    Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2022-34658contributor+≤ 3.2.48

    WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities

    Medium 5.4
  • CVE-2022-2101contributor+≤ 3.2.46

    Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting

    Medium 5.4
  • CVE-2026-94405unauthenticated≤ 3.3.71

    WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability

    Medium 5.3
  • CVE-2026-39676unauthenticated≤ 3.3.52

    WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2025-12177unauthenticated≤ 3.3.30

    Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key

    Medium 5.3
  • CVE-2025-60092unauthenticated≤ 3.3.25

    WordPress Download Manager Plugin <= 3.3.25 - Sensitive Data Exposure Vulnerability

    Medium 5.3
  • CVE-2024-11768unauthenticated≤ 3.3.03

    Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files

    Medium 5.3
  • CVE-2023-6785unauthenticated≤ 3.2.84

    Download Manager <= 3.2.84 - Missing Authorization

    Medium 5.3
  • CVE-2025-60093unauthenticated · needs a click≤ 3.3.24

    WordPress Download Manager Plugin <= 3.3.24 - Cross Site Request Forgery (CSRF) Vulnerability

    Medium 4.3
  • CVE-2026-2571subscriber+≤ 3.3.49

    Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter

    Medium 4.3
  • CVE-2025-13498subscriber+≤ 3.3.32

    Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure

    Medium 4.3
  • CVE-2025-63070login required≤ 3.3.32

    WordPress Download Manager plugin <= 3.3.32 - Sensitive Data Exposure vulnerability

    Medium 4.3
  • CVE-2026-4057contributor+≤ 3.3.51

    Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal

    Medium 4.3
  • CVE-2013-7319

    Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitra

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory