📦

download_manager

Vendor: w3eden

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 3 Remote Access
Total CVEs 120 Total Indexed
Avg. EPSS 1.44% Exploit Prob.
Latest CVE CVE-2025-4367 Jun 19

Security Vulnerability Index

Page 5 / 12
6.5 CVSS

Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.

EPSS: 1.33%
6.1 CVSS
CVE-2019-15889
Exploit Found

The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

EPSS: 12.53%
6.1 CVSS

The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.

EPSS: 0.92%
8.8 CVSS
CVE-2014-9260
Exploit Found

The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.

EPSS: 11.06%
6.1 CVSS

Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: 1.48%
6.1 CVSS

Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.43%
5.0 CVSS

Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.

EPSS: 2.85%
4.3 CVSS
CVE-2013-7319
Exploit Found

Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.

EPSS: 4.58%