Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter
Download Manager
Minimum safe version
3.3.54
Update to 3.3.54 or later to address 105 fixable vulnerabilities
Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter
Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter
Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal
CVE-2026-39676
CVE-2026-39615
CVE-2025-15364
CVE-2025-13498
CVE-2025-63070
CVE-2025-12177
CVE-2025-60092
CVE-2025-60093
Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode
Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion
Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
CVE-2024-13126
Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite
CVE-2024-56217
CVE-2024-10706
CVE-2024-11768
CVE-2024-11740
CVE-2024-8444
Download Manager <= 3.2.98 - Authenticated (Admin+) Stored Cross-Site Scripting
CVE-2024-6208
CVE-2024-2098
CVE-2024-1766
CVE-2024-5266
CVE-2024-4001
CVE-2024-4160
CVE-2024-32131
CVE-2024-29114
CVE-2023-6954
CVE-2023-6785
CVE-2023-6421
CVE-2023-1524
CVE-2023-2305
Download Manager <= 2.5.8 - Cross-Site Scripting
Download Manager <= 2.2.2 - Cross-Site Scripting
WordPress Download Manager <= 2.7.4 - Remote Code Execution
WordPress Download Manager <= 2.7.94 - Stored Cross-Site Scripting
Download Manager <= 2.8.7 - Missing Authorization
Download Manager <= 2.8.7 - Privilege Escalation
Download Manager <= 2.8.7 - Sensitive Information Disclosure via Directory Listing
WordPress Download Manager <= 2.9.45 - Cross-Site Request Forgery
WordPress Download Manager <= 2.9.6 - Cross-Site Request Forgery
WordPress Download Manager <= 2.9.96 - Cross-Site Scripting
CVE-2022-4476
Download Manager <= 3.1.17 - Missing Authorization
WordPress Download Manager < 3.1.19 - Arbitrary File Upload
WordPress Download Manager < 3.1.23 - Arbitrary Asset Manager Usage
WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery
WordPress Download Manager <= 3.2.12 - Cross-Site Request Forgery
Download Manager <= 3.2.43 - Reflected Cross-Site Scripting
Download Manager <= 3.2.53 - Reflected Cross-Site Scripting
CVE-2022-45836
WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)
Download Manager <= 2.2.2 - admin.php cid Parameter XSS
Download Manager <= 2.7.4 - Code Execution / Remote File Inclusion
Download Manager <= 2.7.94 - Authenticated Stored XSS
Download Manager <= 2.8.7 - Multiple Vulnerabilities
Download Manager <= 2.9.45 - Cross-Site Request Forgery (CSRF)
Download Manager <= 2.9.60 - Cross-Site Request Forgery (CSRF)
Download Manager <= 2.9.96 - Various Sanitisation Issues
WordPress Download Manager < 3.1.18 - Unauthorised Download Duplication
Download Manager < 3.1.23 - Unauthorised Asset Manager Usage
Download Manager < 3.1.22 - Plugin Settings Change via CSRF
Download Manager < 3.1.19 - Authenticated (author+) PHP4 File Upload to RCE
WordPress Download Manager < 3.2.13 - Email Template Setting Update via CSRF
Download Manager < 3.2.44 - Unauthenticated Reflected Cross-Site Scripting
Download Manager < 3.2.53 - Unauthenticated Reflected Cross-Site Scripting
CVE-2022-2926
CVE-2022-2431
CVE-2022-2436
CVE-2022-2362
CVE-2022-34347
CVE-2022-34658
CVE-2022-36288
CVE-2022-2168
WordPress Download Manager plugin <= 3.2.43 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2022-2101
WordPress Download Manager 2.7.4 - Remote Code Execution
WordPress Download Manager Plugin <= 2.2.2 - XSS
WordPress Download Manager Free 2.7.94 & Pro 4 - Authenticated Stored XSS
WordPress Download Manager Plugin <= 2.7.94 - Stored XSS
WordPress Download Manager Plugin <= 2.8.7 - Multiple Vulnerabilities
CVE-2022-1985
WordPress Download Manager plugin <= 2.8.97 - Authenticated Arbitrary File Upload Vulnerability
WordPress Download Manager plugin <=2.9.60 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Download Manager plugin <= 2.9.93 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress Download Manager plugin <= 2.9.96 - Multiple vulnerabilities
WordPress Download Manager plugin <= 3.2.12 - Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0828
CVE-2013-7319
CVE-2014-8585
WordPress Download Manager < 2.9.51 - Open Redirect
CVE-2017-2216
CVE-2014-9260
CVE-2017-18032
CVE-2019-15889
CVE-2021-34639
CVE-2021-34638
CVE-2021-24773
CVE-2021-24969
CVE-2021-25069
CVE-2021-25087