{"error":0,"message":null,"data":{"name":"Download Manager","plugin":"download-manager","link":"https:\/\/wordpress.org\/plugins\/download-manager\/","latest":"1789625220","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"0c2199ae292705dfa5c6824b651d9470d6049d8f068db5aba1662830863693d9","name":"Download Manager [download-manager] < 3.2.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-25087","name":"CVE-2021-25087","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-25087","description":"[en] The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).","date":"2022-03-07"},{"id":"a45b87e4d16ec3959e1825bfadcb3ca43de25f1a","name":"WordPress Download Manager plugin <= 3.2.24 - Sensitive Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-24-sensitive-information-disclosure-vulnerability","description":"Sensitive Information Disclosure vulnerability discovered by Diogo Real in WordPress Download Manager plugin (versions <= 3.2.24).","date":"2022-02-02"},{"id":"d7ceafae-65ec-4e05-9ed1-59470771bf07","name":"Wordpress Download Manager &lt; 3.2.25 - Sensitive Information Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/d7ceafae-65ec-4e05-9ed1-59470771bf07","description":"The plugin does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).","date":null},{"id":"78bcc240b2304fd291c5b9ff4e01f5d4cea90b61","name":"Download Manager <= 3.2.34 - Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3234-sensitive-information-disclosure","description":"The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).","date":"2022-02-02"},{"id":"EUVD-2021-11999","name":"EUVD-2021-11999","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2021-11999","description":"Malicious code in bioql (PyPI)","date":"2025-10-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"epss":"0.012"}},{"uuid":"e0805decdfca93da56db361f4efdc530e6ccb68665b3b3b9fc71483b344ff9fa","name":"Download Manager [download-manager] < 3.2.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-25069","name":"CVE-2021-25069","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-25069","description":"[en] The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue","date":"2022-02-21"},{"id":"5542dbd5b7ac0d1ba18c94e8644261bed2d29cef","name":"WordPress Download Manager plugin <= 3.2.33 - Authenticated SQL injection (SQLi) vulnerability to Reflected XSS vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-33-sql-injection-sqli-vulnerability","description":"Authenticated SQL injection (SQLi) vulnerability to Reflected XSS vulnerability discovered by Krzysztof Zaj\u0105c in WordPress Download Manager plugin (versions <= 3.2.33).","date":"2022-01-12"},{"id":"4ff5e638-1b89-41df-b65a-f821de8934e8","name":"WordPress Download Manager &lt; 3.2.34 - Authenticated SQL Injection to Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/4ff5e638-1b89-41df-b65a-f821de8934e8","description":"The plugin does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue","date":null},{"id":"3059283bdef95b58ae09f06d110f13d3972f297d","name":"WordPress Download Manager <= 3.2.33 - Authenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3233-authenticated-sql-injection","description":"The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue","date":"2022-01-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"7ec69f0c2d82fda3e746a39be096a70d134ebcb1393ea7b033dad7c543f3753d","name":"Download Manager [download-manager] < 3.2.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24969","name":"CVE-2021-24969","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24969","description":"[en] The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks","date":"2021-12-27"},{"id":"74dfc552b31066a425b0b9d62142644bc731945e","name":"WordPress Download Manager plugin <= 3.2.21 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-21-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Krzysztof Zaj\u0105c in WordPress Download Manager plugin (versions <= 3.2.21).","date":"2021-11-29"},{"id":"01144c50-54ca-44d9-9ce8-bf4f659114ee","name":"Download Manager &lt; 3.2.22 - Subscriber+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/01144c50-54ca-44d9-9ce8-bf4f659114ee","description":"The plugin does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks","date":null},{"id":"2f040e17fe16ac884ec408fa0a4811bdd6c8228b","name":"WordPress Download Manager <= 3.2.21 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3221-cross-site-scripting","description":"The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks","date":"2021-11-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"bb9587d5e578a8cbec7c6c29fd3e8860ea4a36bbe2dd906bc45a0a6557d38765","name":"Download Manager [download-manager] < 3.2.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24773","name":"CVE-2021-24773","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24773","description":"[en] The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed","date":"2021-11-01"},{"id":"8d16a2ef55f43db81c85cf97428c58d9f44bbad3","name":"WordPress WordPress Download Manager plugin <= 3.2.15 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-wordpress-download-manager-plugin-3-2-15-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Huy Nguyen (Inval1d Team) in WordPress WordPress Download Manager plugin (versions <= 3.2.15).","date":"2021-09-29"},{"id":"aab2ddbb-7675-40fc-90ee-f5bfa8a5b995","name":"WordPress Download Manager &lt; 3.2.16 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/aab2ddbb-7675-40fc-90ee-f5bfa8a5b995","description":"The plugin does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed","date":null},{"id":"c5d26132105ee9f695501fbbcb75898faf15bca2","name":"WordPress Download Manager <= 3.2.15 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3215-cross-site-scripting","description":"The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed","date":"2021-09-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f5d773456571f7ace951a2e25d12e81dc510e217f37c0a5a1ef4a2007b358993","name":"Download Manager [download-manager] < 3.1.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-34638","name":"CVE-2021-34638","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-34638","description":"[en] Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.","date":"2021-08-05"},{"id":"24bcb25f-89b0-44b8-a2e2-f715fd0010ff","name":"WordPress Download Manager &lt; 3.1.25 - Authenticated Directory Traversal","link":"https:\/\/wpscan.com\/vulnerability\/24bcb25f-89b0-44b8-a2e2-f715fd0010ff","description":"Authenticated Directory Traversal in WordPress Download Manager &lt;= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension.","date":null},{"id":"149c85a2aa63d8b9ab4921b1daf2180848f1deaa","name":"WordPress Download Manager <= 3.1.24 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3124-cross-site-scripting","description":"Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.","date":"2021-07-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."},{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-540","name":"Inclusion of Sensitive Information in Source Code","description":"Source code on a web server or repository often contains sensitive information and should generally not be accessible to users."}]}},{"uuid":"6c1573daf1f2180eaf7071f9269e7ac31eed44a07d9485ff868d031aeaa80e60","name":"Download Manager [download-manager] < 3.1.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-34639","name":"CVE-2021-34639","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-34639","description":"[en] Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. \"payload.php.png\" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.","date":"2021-08-05"},{"id":"1c2440c7e834b2d9c1b82a7d2d0fe00cded9cf43","name":"WordPress WordPress Download Manager plugin <= 3.1.24 - Authenticated Directory Traversal vulnerability","link":"https:\/\/patchstack.com\/database\/vulnerability\/download-manager\/wordpress-wordpress-download-manager-plugin-3-1-24-authenticated-directory-traversal-vulnerability","description":"Authenticated Directory Traversal vulnerability discovered by Ramuel Gall (WordFence) in WordPress WordPress Download Manager plugin (versions <= 3.1.24).","date":"2021-07-29"},{"id":"19a8a51ade3c0f6a84bf6596b599266811e02902","name":"WordPress WordPress Download Manager plugin <= 3.1.24 - Authenticated File Upload vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-wordpress-download-manager-plugin-3-1-24-authenticated-file-upload-vulnerability","description":"Authenticated File Upload vulnerability discovered by Ramuel Gall (WordFence) in WordPress WordPress Download Manager plugin (versions <= 3.1.24).","date":"2021-07-29"},{"id":"066947e2-cee1-4ae0-9158-a5750f2ac554","name":"WordPress Download Manager &lt; 3.1.25 - Authenticated File Upload","link":"https:\/\/wpscan.com\/vulnerability\/066947e2-cee1-4ae0-9158-a5750f2ac554","description":"Authenticated File Upload in WordPress Download Manager &lt;= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. &quot;payload.php.png&quot; which is executable in some configurations. The destination folder is also protected by an .htaccess file affecting the same configurations so this is likely difficult to exploit in the real world.","date":null},{"id":"e8c9bd4c9803e0d0acab39625b07f4fc1a5e0321","name":"WordPress Download Manager <= 3.1.24 - Authenticated File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3124-authenticated-file-upload","description":"Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. \"payload.php.png\" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.","date":"2021-07-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."},{"cwe":"CWE-646","name":"Reliance on File Name or Extension of Externally-Supplied File","description":"The product allows a file to be uploaded, but it relies on the file name or extension of the file to determine the appropriate behaviors. This could be used by attackers to cause the file to be misclassified and processed in a dangerous fashion."}]}},{"uuid":"d371485f340fd10e008fb1e500e1cb9257c2e02f334eb1790378d5452f7e8b3b","name":"Download Manager [download-manager] < 2.9.94","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.94","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15889","name":"CVE-2019-15889","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15889","description":"[en] The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.","date":"2019-09-03"},{"id":"333d63eb-7846-4cc3-abd9-b00e12b25037","name":"Download Manager &lt;= 2.9.93 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/333d63eb-7846-4cc3-abd9-b00e12b25037","description":"In the pro features of the WordPress download manager plugin, there is a Category Short-code feature witch can use to sort categories with order by a function which will be used as ?orderby=title,publish_date .\r\nBy adding parameter &quot;&gt; and add any XSS payload , the xss payload will execute.\r\n\r\nTo reproduce,\r\n\r\n1. Go to the link where we can find ?orderby\r\n2. Add parameters &gt;&quot; and give simple payload like &lt;script&gt;alert(1)&lt;\/script&gt;\r\n3. The payload will execute.\r\n\r\nAnother reflected cross-site scripting via advance search .","date":null},{"id":"6d8a1b174233cb3d24a99d251604ead88f92dcb3","name":"WordPress Download Manager <= 2.9.93 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-2993-cross-site-scripting","description":"The WordPress Download Manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.","date":"2019-04-13"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7a47e3348872f3c3bf9a81b61b5d575dc7b9aef823a97fcbdd07f4f69c3579a8","name":"Download Manager [download-manager] < 2.9.52","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.52","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18032","name":"CVE-2017-18032","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18032","description":"[en] The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin\/admin-ajax.php.","date":"2018-01-16"},{"id":"7110da99-300b-4b6f-8f22-6ab65f377948","name":"Download Manager &lt;= 2.9.51 - Authenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/7110da99-300b-4b6f-8f22-6ab65f377948","description":"The WordPress Download Manager WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"59f6d929a515490da2ec793d13586ab795ab3f73","name":"WordPress Download Manager <= 2.9.51 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-2951-cross-site-scripting","description":"The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin\/admin-ajax.php.","date":"2017-06-16"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"836f8aa6a3b73ff030d0bba027a4d670f86d52960d7fb305a32cef4c176e9532","name":"Download Manager [download-manager] < 2.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-9260","name":"CVE-2014-9260","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9260","description":"[en] The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.","date":"2017-08-07"},{"id":"923027bcedfea9404c737d44fda23a10b82e8775","name":"WordPress Download Manager Plugin 2.7.2 - Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-2-7-2-privilege-escalation","description":"Download Manager plugin is prone tu vulnerability that allows an attacker to take control of every group (change name, description, avatar and settings). In this case, every registered user can update every WordPress options using basic_settings() function.\nUpdate to version 2.7.3.","date":"2014-11-24"},{"id":"376c52f7-5ecf-4720-a6c7-29c9693b6e1d","name":"Download Manager &lt;= 2.7.2 - Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/376c52f7-5ecf-4720-a6c7-29c9693b6e1d","description":"The WordPress Download Manager WordPress plugin was affected by a Privilege Escalation security vulnerability.","date":null},{"id":"00d390bf95f5834d37acc10c5dc61041b0b83bd5","name":"WordPress Download Manager <= 2.7.2 - Authenticated Arbitrary Options Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-272-authenticated-arbitrary-options-update","description":"The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.","date":"2014-11-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"}}},{"uuid":"9d212c5a960fa474bc602d34a630ddf4d98dcbe282bff9490f12f72e6b91e72e","name":"Download Manager [download-manager] < 2.9.50","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.50","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-2216","name":"CVE-2017-2216","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-2216","description":"[en] Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","date":"2017-07-07"},{"id":"JVNDB-2017-000127","name":"Cross-site scripting vulnerability in WordPress plugin \"WordPress Download Manager\"","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2017-000127","description":"The WordPress plugin \"WordPress Download Manager\" provided by W3 Eden, Inc. contains a cross-site scripting vulnerability (CWE-79).  Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.","date":"2017-06-13"},{"id":"8d478135-7d48-4979-829f-fee236778420","name":"Download Manager &lt;= 2.9.49 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/8d478135-7d48-4979-829f-fee236778420","description":"The WordPress Download Manager WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"9949b85fc515562359e4871a27a527cd74a79d9d","name":"WordPress Download Manager <= 2.9.49 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-2949-reflected-cross-site-scripting","description":"The WordPress Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in versions up to, and including, 2.9.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2017-06-13"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"6710d53f65b6333c8b711068a3a975fa4af126e1211884a30b5381a1001d0b51","name":"Download Manager [download-manager] < 2.9.51","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.51","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-2217","name":"CVE-2017-2217","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-2217","description":"[en] Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.","date":"2017-07-07"},{"id":"JVNDB-2017-000128","name":"Open redirect vulnerability in WordPress plugin \"WordPress Download Manager\"","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2017-000128","description":"The WordPress plugin \"WordPress Download Manager\" provided by W3 Eden, Inc. contains an open redirect vulnerability (CWE-601).  Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.","date":"2017-06-13"},{"id":"a244cd45-e09c-44f6-8796-de96492b0567","name":"Download Manager &lt;= 2.9.50 - Open Redirect","link":"https:\/\/wpscan.com\/vulnerability\/a244cd45-e09c-44f6-8796-de96492b0567","description":"The WordPress Download Manager WordPress plugin was affected by an Open Redirect security vulnerability.","date":null},{"id":"b9059e1a8579e2a058e8497f99a922f5e2c5ec6d","name":"WordPress Download Manager < 2.9.51 - Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-2951-open-redirect","description":"Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.","date":"2017-07-13"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}]}},{"uuid":"05c878428afe7513af4f642d3d1255d118226a59ecb3d142e994c6ea12f328cf","name":"Download Manager [download-manager] < 2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-8585","name":"CVE-2014-8585","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-8585","description":"[en] Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views\/file_download.php or (2) file_download.php.","date":"2014-11-04"},{"id":"d5ad89146b0682530c6955a7e9e4be4dd0d83f2b","name":"WordPress Download Manager Plugin - Arbitrary File Download","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-arbitrary-file-download","description":"Because of this vulnerability, the  attackers can read arbitrary files in the \"fname\" parameter to views\/file_download.php or file_download.php.\nUpdate the plugin.","date":"2014-11-04"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-59","name":"Improper Link Resolution Before File Access ('Link Following')","description":"The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource."}]}},{"uuid":"2b53710067b16883da3781b5d68244c9497d47bad584268798a054b98e0c4778","name":"Download Manager [download-manager] < 2.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2013-7319","name":"CVE-2013-7319","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2013-7319","description":"[en] Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.","date":"2014-02-06"},{"id":"68913c8f1ad7da630edccf7040cdd3f03bbbfeea","name":"WordPress Download Manager Free & Pro Plugin 2.5.8 - Persistent Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-free-pro-plugin-2-5-8-persistent-cross-site-scripting","description":"Download Manager Free & Pro plugin is prone to a persistent XSS vulnerability. The title input\r\nfield is not sanitized and therefor vulnerable to persistent cross site scripting.\nUpgrade the plugin.","date":"2013-12-08"},{"id":"507b934d-5776-45e0-8f16-ed092091aa0b","name":"Download Manager &lt;= 2.5.8 - Download Package file Parameter Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/507b934d-5776-45e0-8f16-ed092091aa0b","description":"The WordPress Download Manager WordPress plugin was affected by a Download Package file Parameter Stored XSS security vulnerability.","date":null},{"id":"f11f4d0496bd5ce0d037a5e2a72f14b83b29b52f","name":"Download Manager < 2.5.9 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-259-stored-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.","date":"2013-12-08"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"8c709017ae6dbd8c1d344d096e9e29aba635654f422d64b9d57f43bf9b4a2141","name":"Download Manager [download-manager] < 3.2.39","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.39","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0828","name":"CVE-2022-0828","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0828","description":"[en] The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.","date":"2022-04-11"},{"id":"59431aa734f7052d17d12e5b7bd64750b885cbdb","name":"WordPress Download Manager plugin <= 3.2.38 - Unauthenticated Brute Force of Files Master Key vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-38-unauthenticated-brute-force-of-files-master-key-vulnerability","description":"Unauthenticated Brute Force of Files Master Key vulnerability discovered by Diogo Real in WordPress Download Manager plugin (versions <= 3.2.38).","date":"2022-03-16"},{"id":"7f0742ad-6fd7-4258-9e44-d42e138789bb","name":"Download Manager &lt; 3.2.39 - Unauthenticated brute force of files master key","link":"https:\/\/wpscan.com\/vulnerability\/7f0742ad-6fd7-4258-9e44-d42e138789bb","description":"The plugin uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.","date":null},{"id":"4042da3011bcdb08e5cd8588e833d8638be4ab08","name":"Download Manager <= 3.2.38 - Unauthenticated Brute Force of File Master Key","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3238-unauthenticated-brute-force-of-file-master-key","description":"The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.","date":"2022-03-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-338","name":"Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)","description":"The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong."}]}},{"uuid":"d569e6fcb6f4bfeebd6677eee7ead089cf42cf8c1b9fffec34b5cee5caba1568","name":"Download Manager [download-manager] < 3.2.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a8d63261acfeea228c370d3682acda5dfc385b49","name":"WordPress Download Manager plugin <= 3.2.12 - Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-12-email-template-setting-update-via-cross-site-request-forgery-csrf-vulnerability","description":"Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Download Manager plugin (versions <= 3.2.12).","date":"2021-08-09"}],"impact":[]},{"uuid":"3ae33da6c23d6e2e5b3ff9daf14deada52d3778d2497123e8e2f8a2beebf8dce","name":"Download Manager [download-manager] < 2.9.97","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.97","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"48e30762d6539a7eee45478972c929e51e64166d","name":"WordPress Download Manager plugin <= 2.9.96 - Multiple vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-2-9-96-multiple-vulnerabilities","description":"Multiple vulnerabilities found in WordPress Download Manager plugin (versions <= 2.9.96).","date":"2019-06-16"}],"impact":[]},{"uuid":"48cf25a33cc8566e61adb6960dfcb891654b4bca283d42777ab568fc626d19b8","name":"Download Manager [download-manager] < 2.9.94","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.94","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"64e4c85301ceb67932089f2b99f60f1b13e950bf","name":"WordPress Download Manager plugin <= 2.9.93 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-2-9-93-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability found by MgThuraMoeMyint on WordPress Download Manager plugin (versions <= 2.9.93).","date":"2019-04-23"}],"impact":[]},{"uuid":"ef7d3b3720162b41521a22016137519ac99cd5f568630cd03e4d929ed4db9f11","name":"Download Manager [download-manager] < 2.9.61","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.61","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"22a2e7b0e1328bdfcd9abdf7258c7bf9cdb14680","name":"WordPress Download Manager plugin <=2.9.60 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-2-9-60-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found by Panagiotis Vagenas in WordPress Download Manager plugin (versions <=2.9.60).","date":"2018-01-10"}],"impact":[]},{"uuid":"43e077aed7e56fa4669cab129aad41f0798158a526876034c8400c30be2856f4","name":"Download Manager [download-manager] < 2.9.46","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.46","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dcd868a17d34d1cc7c03e424780d2c8efb3bb492","name":"WordPress Download Manager plugin <= 2.8.97 - Authenticated Arbitrary File Upload Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-wordpress-download-manager-plugin-2-8-97-authenticated-arbitrary-file-upload-vulnerability","description":"Authenticated Arbitrary File Upload Vulnerability exsists in WordPress WordPress Download Manager plugin <= 2.8.97 . It doesn't check what type of files you can upload so an attacker can upload .PHP files.\nUpdate the plugin.","date":"2017-06-27"}],"impact":[]},{"uuid":"2eb45756d31eef1e5c9c5825a6e72818a39a2e65a8c02b483fe2cd674ed9e549","name":"Download Manager [download-manager] < 3.2.43","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.43","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1985","name":"CVE-2022-1985","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1985","description":"[en] The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~\/src\/Package\/views\/shortcode-iframe.php file.","date":"2022-06-13"},{"id":"ad2289c504418d487b70384e35ee4f5fc6341851","name":"WordPress Download Manager plugin <= 3.2.42 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-42-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Rafie Muhammad (Yeraisci) in WordPress Download Manager plugin (versions <= 3.2.42).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.43).","date":"2022-06-07"},{"id":"19352d3c-6346-49d8-a673-e9f4882c5907","name":"Download manager &lt; 3.2.43 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/19352d3c-6346-49d8-a673-e9f4882c5907","description":"The plugin does not sanitise and escape the frameid parameter before outputting it back in a JS context, leading to a Reflected Cross-Site Scripting","date":null},{"id":"aea9cbbde41566b4083d5d82ba0c32dfd6a8a5dd","name":"Download Manager <= 3.2.42 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3242-reflected-cross-site-scripting","description":"The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~\/src\/Package\/views\/shortcode-iframe.php file.","date":"2022-06-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"533e838e88a3245118df5a83cf3d10ebcffd4d0b761a2445c28c3a2bc1778de9","name":"Download Manager [download-manager] < 2.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"43f75deeeade722676f3b4836a0f47b56479e1c3","name":"WordPress Download Manager Plugin <= 2.8.7 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-2-8-7-multiple-vulnerabilities","description":"This plugin is prone to privilege escalation, unauthenticated directory listings and unauthenticated post updating vulnerabilities.\nUpdate the plugin.","date":"2016-01-19"}],"impact":[]},{"uuid":"0e6425889f9b47a74f0e4df222cdb57242e0267185750654cb808277a041fbed","name":"Download Manager [download-manager] < 2.7.95","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.95","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e27ab2277e8017a6079888199a72ae641e378e1e","name":"WordPress Download Manager Plugin <= 2.7.94 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-2-7-94-stored-xss","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-12-20"}],"impact":[]},{"uuid":"e8e971985322aed1dac771ac5ee8e2907b20b827e6bd3402d173e03588dec8f8","name":"Download Manager [download-manager] < 2.7.95","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.95","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dc77633354921d8fde420d9502ad22bee58a2399","name":"WordPress Download Manager Free 2.7.94 & Pro 4 - Authenticated Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-free-2-7-94-pro-4-authenticated-stored-xss","description":"Download Manager Free and Pro is prone to an authenticated stored XSS that allows an attacker to create new download package and upload files, called <svg onload=alert(0)>.jpg. This vulnerability works, when user try to edit this download package.\nUpgrade to the latest version.","date":"2015-07-16"}],"impact":[]},{"uuid":"a8502c5230c5b814f72d4494648131e2e3de19c0dde47d831d1b7c2fd3192191","name":"Download Manager [download-manager] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ea7d1ab6444f8a0a8263d0e893247937cbf5f536","name":"WordPress Download Manager Plugin <= 2.2.2 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-2-2-2-xss","description":"This plugin is prone to admin.php cid parameter cross site scripting vulnerability.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"1bd602be741809d6103b7b1c7dd8b52a7ee46bb7f1a9da35430ce09a0f3a381e","name":"Download Manager [download-manager] >= 2.7.0 - <= 2.7.4","description":null,"operator":{"min_version":"2.7.0","min_operator":"ge","max_version":"2.7.4","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"2dbefbf8b0b9f63fcb15ce856bdbeb59159cb13d","name":"WordPress Download Manager 2.7.4 - Remote Code Execution","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-2-7-4-remote-code-execution","description":"Download Manager plugin is prone to a remote code execution vulnerability via \"\/download-manager\/wpdm-core.php\". It allows attackers to execute arbitrary PHP code.\nUpgrade the plugin.","date":"2014-12-15"}],"impact":[]},{"uuid":"653218243db04243c94c6034b10fb8460bb37f7034765fe16e912980e452adf6","name":"Download Manager [download-manager] < 3.2.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2101","name":"CVE-2022-2101","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2101","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page.","date":"2022-07-18"},{"id":"dbcca77a92ac1a15e9e16f0c606c1cb14307545c","name":"WordPress Download Manager plugin <= 3.2.45 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/vulnerability\/download-manager\/wordpress-download-manager-plugin-3-2-45-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability was discovered by Andrea Bocchetti in the WordPress Download Manager plugin (versions <= 3.2.45).\nNo patched version available.","date":"2022-06-27"},{"id":"951a71c5bbd894b1232f865a1b601fc70668976c","name":"WordPress Download Manager <= 3.2.46 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-3-2-46-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability discovered by Andrea Bocchetti in WordPress Download Manager (versions <= 3.2.46).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.47).","date":"2022-07-01"},{"id":"68d7e132-bb8c-4e83-b8aa-39067fbd638e","name":"Download Manager &lt; 3.2.48 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/68d7e132-bb8c-4e83-b8aa-39067fbd638e","description":"The plugin does not sanitise and escape the &#039;Insert URL&#039; field, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.\r\n\r\nNote: The attempted fix made in 3.2.46 and 3.2.47 were found to be insufficient","date":null},{"id":"0bf2cd3aed118b8f64f1d359b54cea06e9493270","name":"Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3246-contributor-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page.","date":"2022-06-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d16aa28c96fdaac2e2f039389821b10247ea99320154b1bd8c0f1352ae9f9888","name":"Download Manager [download-manager] < 3.2.44","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.44","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c6db3508368504fe0f4a857a752127f0b8bca795","name":"WordPress Download Manager plugin <= 3.2.43 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-43-unauthenticated-reflected-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Download Manager plugin (versions <= 3.2.43).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.44).","date":"2022-06-27"}],"impact":[]},{"uuid":"a6fec171430ca334dde33d885fa8c1e0e661ec5c662ffce29c3d27a9e83927b7","name":"Download Manager [download-manager] < 3.2.44","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.44","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2168","name":"CVE-2022-2168","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2168","description":"[en] The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting","date":"2022-07-17"},{"id":"6b4cabb15c301c43cc6bf14c1221df865bcf50ae","name":"WordPress Download Manager plugin <= 3.2.43 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-43-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by ZhongFu Su aka JrXnm (WuHan University) in WordPress Download Manager plugin (versions <= 3.2.43).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.44).","date":"2022-06-27"},{"id":"66789b32-049e-4440-8b19-658649851010","name":"Download Manager &lt; 3.2.44 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/66789b32-049e-4440-8b19-658649851010","description":"The plugin does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting","date":null},{"id":"8383eba9ff23835864b17d080cfa50a89b474a24","name":"Download Manager <= 3.2.43 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3243-reflected-cross-site-scripting-2","description":"The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting","date":"2022-06-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"2ce16ba3dbdd85fc582a3c72cb9f333cf0931399b2370dfb6f05f1616785efd7","name":"Download Manager [download-manager] < 3.2.49","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.49","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-36288","name":"CVE-2022-36288","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-36288","description":"[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.","date":"2022-08-23"},{"id":"c371f22acee32c3324f1211f3c5763657fe54e6d","name":"WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-48-multiple-cross-site-request-forgery-csrf-vulnerabilities","description":"Multiple Cross-Site Request Forgery (CSRF) vulnerabilities leading to stats and cache deletion were discovered by Vlad Vector (Patchstack) in the WordPress Download Manager plugin (versions <= 3.2.48).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.49).","date":"2022-08-02"},{"id":"62eeb5bb05fab644b6824a17db0359b294e304e3","name":"Download Manager <= 3.2.48 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3248-cross-site-request-forgery","description":"The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete stats and clear the plugin's cache via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-08-02"},{"id":"fa02aaeb-99db-4925-bdf7-be1840ba7dd2","name":"Download Manager &lt; 3.2.49 - Multiple CSRF","link":"https:\/\/wpscan.com\/vulnerability\/fa02aaeb-99db-4925-bdf7-be1840ba7dd2","description":"The plugin does not have CSRF check in place in some places, which could allow attackers to make a logged in admin perform unwanted actions","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8248ec6853242708925ae0f2bd1d59347858095b2ff5cca0b94886a9645e64d8","name":"Download Manager [download-manager] < 3.2.49","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.49","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-34658","name":"CVE-2022-34658","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-34658","description":"[en] Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.","date":"2022-08-23"},{"id":"b3abdc1a08acb0616baef7cc3b0a5ecdbab17866","name":"WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-48-multiple-authenticated-persistent-cross-site-scripting-xss-vulnerabilities","description":"Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities were discovered by Vlad Vector (Patchstack) in the WordPress Download Manager plugin (versions <= 3.2.48).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.49).","date":"2022-08-02"},{"id":"0fa735a3d196d66459b2cafc5ebaef7f2572d830","name":"Download Manager <= 3.2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3248-authenticated-contributor-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018title\u2019 and 'label' parameters in versions up to, and including, 3.2.48  due to insufficient input sanitization and output escaping when setting lock options for downloadables. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-07-06"},{"id":"f01eeee9-45d0-49ee-8f53-a98992060ab4","name":"Download Manager &lt; 3.2.49 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/f01eeee9-45d0-49ee-8f53-a98992060ab4","description":"The plugin does not sanitise and escape some parameters which could allow users with a role as low as contruibutor to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e4a4a36f9c8497d00cf570b97fe441a769c4a7f6125ac39cd605806fa3ef3c04","name":"Download Manager [download-manager] < 3.2.49","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.49","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-34347","name":"CVE-2022-34347","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-34347","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.","date":"2022-08-22"},{"id":"c7d15b394746fd36e3868bb3508ec0d5c7ca47b7","name":"WordPress Download Manager plugin <= 3.2.48 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-48-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability leading to template status change discovered by Muhammad Daffa (Patchstack Alliance) in WordPress Download Manager plugin (versions <= 3.2.48).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.49).","date":"2022-08-02"},{"id":"2c0b9de5c543ddf10a0d2ddbf431e2fe7234eca4","name":"Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3248-cross-site-request-forgery-to-plugin-settings-update","description":"The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation on the updateTemplateStatus function. This makes it possible for unauthenticated attackers to trigger setting changes forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-08-02"},{"id":"1fe07196-52d4-40c5-b01d-69852b4fb9c5","name":"Download Manager &lt; 3.2.49 - Clear Stats &amp; Cache via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/1fe07196-52d4-40c5-b01d-69852b4fb9c5","description":"The plugin does not have CSRF check in place in some of its action (such as clear cache and stats as well as update template status), which could allow attackers to make a logged in admin call them via CSRF attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"h","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"4.2","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"4.2","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c287a8bb4654fd8346e2cedee71d3ca07bb6e6b49a984ca74042c86a09c2e9e1","name":"Download Manager [download-manager] < 3.2.50","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.50","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2362","name":"CVE-2022-2362","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2362","description":"[en] The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.","date":"2022-08-22"},{"id":"dc30d4c3df3857618561fea135cbddc5c5e28abd","name":"WordPress Download Manager plugin <= 3.2.49 - Bypass IP Address Blocking Restriction vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-49-bypass-ip-address-blocking-restriction-vulnerability","description":"Bypass IP Address Blocking Restriction vulnerability discovered by Raad Haddad in WordPress Download Manager plugin (versions <= 3.2.49).\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.50).","date":"2022-08-01"},{"id":"d94b721e-9ce2-45e5-a673-2a57b0137653","name":"Download Manager &lt; 3.2.50 - Bypass IP Address Blocking Restriction","link":"https:\/\/wpscan.com\/vulnerability\/d94b721e-9ce2-45e5-a673-2a57b0137653","description":"The plugin prioritizes getting a visitor&#039;s IP from certain HTTP headers over PHP&#039;s REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.","date":null},{"id":"0defed059bc64138cb6727ff95c31bc4ca124f67","name":"Download Manager <= 3.2.49 - IP Blocking Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3249-ip-blocking-bypass","description":"The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 due to the way the visitor's IP address is determined. This allows an unauthenticated attacker to spoof their IP address to obtain access to files that are protected by this functionality.","date":"2022-08-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"501377cd4483b966c8c03262efd81108e065387324b2eedc53b4e12dbc752cb3","name":"Download Manager [download-manager] < 3.2.71","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.71","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2436","name":"CVE-2022-2436","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2436","description":"[en] The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.","date":"2022-09-06"},{"id":"9811c70c45bf94d3538ac01a1093ca3eae10feb9","name":"WordPress Download Manager Plugin <= 3.2.49 - Authenticated PHAR Deserialization vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-49-authenticated-phar-deserialization-vulnerability","description":"Authenticated PHAR Deserialization vulnerability discovered by Rasoul Jahanshahi  in Download Manager plugin (versions <= 3.2.49)\nUpdate the WordPress Download Manager plugin to the latest available version (at least 3.2.50).","date":"2022-08-18"},{"id":"d46bdea26b0a77ad3dc0d94aaa1075eb91a5b0b9","name":"Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3249-authenticated-contributor-phar-deserialization","description":"The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.","date":"2022-08-17"},{"id":"493a4626-71f0-4cfc-b1d9-74ca8130045e","name":"Download Manager &lt; 3.2.50 - Contributor+ PHAR Deserialization","link":"https:\/\/wpscan.com\/vulnerability\/493a4626-71f0-4cfc-b1d9-74ca8130045e","description":"The plugin does not validate a parameter, which could allow users with a role as low as contributor to perform PHAR deserialisation when a suitable gadget chain is also present","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"b1032948a4cfd201730fbc2a9c17e828b7d03a3b0c35c3f0acd39d0d538372b3","name":"Download Manager [download-manager] < 3.2.51","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.51","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2431","name":"CVE-2022-2431","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2431","description":"[en] The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~\/Admin\/Menu\/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the \/wp-config.php file which will reset the installation and make it possible for an attacker to achieve remote code execution on the server.","date":"2022-09-06"},{"id":"0f249c1a-ccab-4746-b55b-23d7e3218d24","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/0f249c1a-ccab-4746-b55b-23d7e3218d24","description":null,"date":null},{"id":"890022edd6a37be30f1cae480750c1ece3032c19","name":"Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3250-authenticated-contributor-arbitrary-file-deletion","description":"The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~\/Admin\/Menu\/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the \/wp-config.php file which will reset the installation and make it possible for an attacker to achieve remote code execution on the server.","date":"2022-07-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-73","name":"External Control of File Name or Path","description":"The product allows user input to control or influence paths or file names that are used in filesystem operations."},{"cwe":"CWE-610","name":"Externally Controlled Reference to a Resource in Another Sphere","description":"The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a42e6550a68a74b0ca39c87542b570e0f0bacfffcb0fa6ea0249c73cd6a4dce7","name":"Download Manager [download-manager] < 3.2.55","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.55","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2926","name":"CVE-2022-2926","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2926","description":"[en] The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory","date":"2022-09-26"},{"id":"603959e87af37b02e27fac75c23b55070996914c","name":"Download Manager <= 3.2.54 - Authenticated (Admin+) Path Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3254-authenticated-admin-path-traversal","description":"The Download Manager plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.2.54  via the File Browser Root field. This makes it possible for administrator-level attackers to list and read arbitrary files and folders outside of the blog directory.","date":"2022-09-05"},{"id":"2a440e1a-a7e4-4106-839a-d93895e16785","name":"Download Manager &lt; 3.2.55 - Admin+ Arbitrary File\/Folder Access via Path Traversal","link":"https:\/\/wpscan.com\/vulnerability\/2a440e1a-a7e4-4106-839a-d93895e16785","description":"The plugin does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"1.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"1.2","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e8b2e640c608904773085d29b07b77cb9862d876457d15ae0dd33518a493f41e","name":"Download Manager [download-manager] < 3.2.53","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.53","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"394007c5-7923-46fe-bb4c-2377d66ff900","name":"Download Manager &lt; 3.2.53 - Unauthenticated Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/394007c5-7923-46fe-bb4c-2377d66ff900","description":"The plugin does not escape the $_SERVER[&#039;REQUEST_URI&#039;] parameter before outputting it back in an attribute of the modal login page (only available when users are not logged in), which could lead to Reflected Cross-Site Scripting in old web browsers.","date":null}],"impact":[]},{"uuid":"8c83d5b856fb7fdc912eae3cf4a765af33ac9b94e0c7796456442c0d5feb2389","name":"Download Manager [download-manager] < 3.2.44","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.44","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"95deb79c-bf19-4ab5-aac6-702a13323356","name":"Download Manager &lt; 3.2.44 - Unauthenticated Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/95deb79c-bf19-4ab5-aac6-702a13323356","description":"The plugin does not escape a generated URL before outputting it back in an attribute of the login page made by the plugin, leading to Reflected Cross-Site Scripting, which is only exploitable against unauthenticated users","date":null}],"impact":[]},{"uuid":"558a1149a485d7d41b682f8668f93ec9f4fbaaab27ed2a3f54a062d88bcc4d81","name":"Download Manager [download-manager] < 3.2.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"115a6fd3-a723-4167-a9a3-379871f13fcb","name":"WordPress Download Manager &lt; 3.2.13 - Email Template Setting Update via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/115a6fd3-a723-4167-a9a3-379871f13fcb","description":"The plugin did not have CSRF check in place before saving its Email Template setting, allowing attackers to make a logged in admin change them via a CSRF attack","date":null}],"impact":[]},{"uuid":"5f80f812aad0e49a8c8b88033ea0d5b3c4415bc8bd4e57019e775d3d15b5a7e6","name":"Download Manager [download-manager] < 3.1.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4ca9f811-3461-4dea-938f-1528440e2708","name":"Download Manager &lt; 3.1.19 - Authenticated (author+) PHP4 File Upload to RCE","link":"https:\/\/wpscan.com\/vulnerability\/4ca9f811-3461-4dea-938f-1528440e2708","description":"The wpdm_admin_upload_file AJAX action used a blacklist approach to forbid potential dangerous files, such as PHP, from being uploaded. However, other dangerous extensions, like .php4 were not forbidden.","date":null}],"impact":[]},{"uuid":"48bdf5656b62bd55289b7274bdb8bb84118fba35605c32fc3f35f8c224ba11ab","name":"Download Manager [download-manager] < 3.1.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2a9331b1-1d43-4729-bb0a-9198ffe3d703","name":"Download Manager &lt; 3.1.22 - Plugin Settings Change via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/2a9331b1-1d43-4729-bb0a-9198ffe3d703","description":"The wpdm_settings AJAX action, used the section POST parameter to call the associated settings handler methods dynamically. However, the pluginUpdate() (section=plugin-update) and Privacy() (section=privacy) were missing CSRF checks. Furthermore, the Privacy() function did not ensure that the options to be updated were actually related to privacy, allowing any option key containing _wpdm_ to be updated.","date":null}],"impact":[]},{"uuid":"1c105da1b31411108b626d50ac87a24d1bd1352d0f85fef42662b77b006a56d6","name":"Download Manager [download-manager] < 3.1.23","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.23","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bc88aa10-b861-4426-8bcd-ab1b4a2214ab","name":"Download Manager &lt; 3.1.23 - Unauthorised Asset Manager Usage","link":"https:\/\/wpscan.com\/vulnerability\/bc88aa10-b861-4426-8bcd-ab1b4a2214ab","description":"The majority of the AJAX actions related to the Asset Manager use the same nonce action (ie the NONCE_KEY constant), and are lacking any authorisation checks. Given that the nonce is available in other pages, accessible by low priviledge users (such as author, or even subscribers depending on the plugin&#039;s feature used), this could lead to unauthorised use of the Asset Manager.\r\n\r\nExploitation of the mkDir, newFile, scanDir, createZip, unZip, deleteItem, openFile, fileSettings, saveFile, moveItem, copyItem would be quite difficult to achieve, as their file\/path parameters are encrypted using SECURE_AUTH_KEY or NONCE_SALT, nonetheless, they should be properly secured.\r\n\r\nHowever, the addComment, addShareLink, getLinkDet, updateLink, deleteLink and renameItem can be exploited.","date":null}],"impact":[]},{"uuid":"fb8ff0592918d29410170b3fc00f283b0c3f40c3c7d3acc34cd62eb2086be814","name":"Download Manager [download-manager] < 3.1.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"95facb10-514c-45dc-a164-7aa54741513b","name":"WordPress Download Manager &lt; 3.1.18 - Unauthorised Download Duplication","link":"https:\/\/wpscan.com\/vulnerability\/95facb10-514c-45dc-a164-7aa54741513b","description":"The duplicate() method, hooked to the admin_init action did not have any CSRF and authorisation checks, allowing unauthorised users (such as unauthenticated ones) to duplicate arbitrary downloads","date":null}],"impact":[]},{"uuid":"e58dd7b12315017e75f541568ed5f88b8625f07628d976c13708dfd4fefe4939","name":"Download Manager [download-manager] < 2.9.97","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.97","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ee6104ce-7e85-4bfc-9753-56d942e750ef","name":"Download Manager &lt;= 2.9.96 - Various Sanitisation Issues","link":"https:\/\/wpscan.com\/vulnerability\/ee6104ce-7e85-4bfc-9753-56d942e750ef","description":"The WordPress Download Manager WordPress plugin was affected by a Various Sanitisation Issues security vulnerability.","date":null}],"impact":[]},{"uuid":"66c5f28cce257177a1e8cbb2b928152f329cce561d367b871fd18f6807f7874e","name":"Download Manager [download-manager] < 2.9.61","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.61","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ef20a37f-b2c2-4857-9267-1d5d17166b77","name":"Download Manager &lt;= 2.9.60 - Cross-Site Request Forgery (CSRF)","link":"https:\/\/wpscan.com\/vulnerability\/ef20a37f-b2c2-4857-9267-1d5d17166b77","description":"The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.","date":null}],"impact":[]},{"uuid":"d249781d3592dee39ae5f06820f4f002ca5517094d012ee44478b32c09ade209","name":"Download Manager [download-manager] < 2.9.46","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.46","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4f1196b4-807f-4238-8cfa-82046f786cb4","name":"Download Manager &lt;= 2.9.45 - Cross-Site Request Forgery (CSRF)","link":"https:\/\/wpscan.com\/vulnerability\/4f1196b4-807f-4238-8cfa-82046f786cb4","description":"The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.","date":null}],"impact":[]},{"uuid":"52f050004054632e61d36077c1bef19d207743eb466543ad915589827db1c431","name":"Download Manager [download-manager] < 2.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ea09b240-6add-4278-9a15-5b9e356ebd3c","name":"Download Manager &lt;= 2.8.7 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/ea09b240-6add-4278-9a15-5b9e356ebd3c","description":"Numerous vulnerabilities with WordPress Download Manager free and pro versions. Privilege escalation, directory listing and unauthorised file download.","date":null}],"impact":[]},{"uuid":"0aef5e5b3f228bd5344cf519ff017cac84ec128f50cebae26818cf93552bbedd","name":"Download Manager [download-manager] < 2.7.95","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.95","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2d592bc0-5ab8-43ba-927e-32f8323630bf","name":"Download Manager &lt;= 2.7.94 - Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/2d592bc0-5ab8-43ba-927e-32f8323630bf","description":"The stored XSS vulnerability allows any authenticated user to inject malicious code via the name of the uploaded file:\r\n\r\nExample: &lt;svg onload=alert(0)&gt;.jpg\r\n\r\nThe vulnerability exists because the file name is not properly sanitized \r\nand this can lead to malicious code injection that will be executed on the \r\ntarget&rsquo;s browser.","date":null}],"impact":[]},{"uuid":"27cc9aed9aa12c7c3cc57a61717a50d8194c521709f4046c5acde1b0981ac01b","name":"Download Manager [download-manager] < 2.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b0ac361a-bad1-48f0-9554-3fca6c67054c","name":"Download Manager &lt;= 2.7.4 - Code Execution \/ Remote File Inclusion","link":"https:\/\/wpscan.com\/vulnerability\/b0ac361a-bad1-48f0-9554-3fca6c67054c","description":"The WordPress Download Manager WordPress plugin was affected by a Code Execution \/ Remote File Inclusion security vulnerability.","date":null}],"impact":[]},{"uuid":"728d6a2d55f3567c81bf37c459692d9d61b2111c5b3069d64b4679c8b2423757","name":"Download Manager [download-manager] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ec0c6d34-515c-4d6b-8ee0-af0f45b9705a","name":"Download Manager &lt;= 2.2.2 - admin.php cid Parameter XSS","link":"https:\/\/wpscan.com\/vulnerability\/ec0c6d34-515c-4d6b-8ee0-af0f45b9705a","description":"The WordPress Download Manager WordPress plugin was affected by an admin.php cid Parameter XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"af8aaaa6913b3d1739310eeb11429d35f1a63357b6b5e7fbab3994046506ee34","name":"Download Manager [download-manager] < 3.2.60","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.60","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"475bb8d46bd97d6fc2a097080b3f99a444f3d59d","name":"WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-59-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Download Manager plugin to the latest available version (at least 3.2.60).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.2.60.","date":null}],"impact":[]},{"uuid":"7ea6f01216f9060c9356400b66b2cf926fd78dade564bce0d83ff855b83842d4","name":"Download Manager [download-manager] < 3.2.60","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.60","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-45836","name":"CVE-2022-45836","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-45836","description":"[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <=\u00a03.2.59 versions.","date":"2023-04-18"},{"id":"8c6712073065302afcc0cdb4fc7aa6c2901ef402","name":"Download Manager <= 3.2.59 - Refleced Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3259-unauthenticated-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018packages-shortcode-toolbar.php\u2019, 'Shortcodes.php', and 'category-shortcode-toolbar.php' (in both 'src\/Package\/views\/' and 'src\/Category\/views\/') files in versions up to, and including, 3.2.59 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute if they can successfully trick a victim into clicking on a link.","date":"2022-11-29"},{"id":"8d51a252-daef-40a9-9ffb-1b51f5c6f957","name":"Download Manager &lt; 3.2.60 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/8d51a252-daef-40a9-9ffb-1b51f5c6f957","description":"The plugin does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f94bdb47ae71e6f2e8687ae3c9d651c13b49d302a459af3b71430e0653f6ba19","name":"Download Manager [download-manager] < 3.2.54","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.54","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f0882d39ee4fe7bd5f3cbc58ec5a01067f2336a9","name":"Download Manager <= 3.2.53 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3253-reflected-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2022-08-04"}],"impact":[]},{"uuid":"a2c624fb74dc2713e82ad29e14cb991755c96bfab534c612d1c4ac95e192c0af","name":"Download Manager [download-manager] < 3.2.44","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.44","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"28dc54841f3431e6c1ae619323673953e6c9ad07","name":"Download Manager <= 3.2.43 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3243-reflected-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2022-06-23"}],"impact":[]},{"uuid":"82512c50299b23c06420eae6564a2f07dd5f0d2861d109a748dbbfaa8d0492f2","name":"Download Manager [download-manager] < 3.2.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d4451caae529c7afd19fe3b86e0b1e84960afd50","name":"WordPress Download Manager <= 3.2.12 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3212-cross-site-request-forgery","description":"The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for unauthenticated attackers to save the plugins email settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2021-08-09"}],"impact":[]},{"uuid":"a8aace54c9586850b641eecb850aa917ec69a277fca29bb44835d336b4bb5a55","name":"Download Manager [download-manager] < 3.1.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9f865ea2da941668d15a46e0d2f58ce77f2047df","name":"WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3122-cross-site-request-forgery","description":"The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2021-04-30"}],"impact":[]},{"uuid":"a4f8ce255113521130c48484bf6e9d96d4dd7da092ab81b4502da3deea96203f","name":"Download Manager [download-manager] < 3.1.23","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.23","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1cc47941b582e70eb3c7a084fea122889f7c8f61","name":"WordPress Download Manager < 3.1.23 -  Arbitrary Asset Manager Usage","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3123-arbitrary-asset-manager-usage","description":"The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers with low level privileges to reveal the nonce in pages available to them and use it to perform unauthorized actions.","date":"2021-04-30"}],"impact":[]},{"uuid":"7720aaf71a63693c4dedaafaac960003fc5ab757036e94cd3c16518827cfb14b","name":"Download Manager [download-manager] < 3.1.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"413f54781ffb5ef3531adbeaaf6527a75a4cd160","name":"WordPress Download Manager < 3.1.19 - Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-3119-arbitrary-file-upload","description":"The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level privileges and above to upload arbitrary files on the affected sites server which may make remote code execution possible.","date":"2021-04-30"}],"impact":[]},{"uuid":"fec2a270b9f4759fa9b96aa35b0964f0fedae446f7c7dae37b39e089982c5f9d","name":"Download Manager [download-manager] < 3.1.17","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.17","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bf80a7f6a2d48f38eeb6ada67189ba397eff748a","name":"Download Manager <= 3.1.17 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3117-missing-authorization","description":"The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable sites downloads.","date":"2021-04-16"}],"impact":[]},{"uuid":"c9046aa12f9e8cd87584cbaeac08073ce6866ebbdf615fe62fd8e56d3cd4cd54","name":"Download Manager [download-manager] < 3.2.62","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.62","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-4476","name":"CVE-2022-4476","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4476","description":"[en] The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.","date":"2023-01-16"},{"id":"3d5777a76f63af8b7a5d4d4e8b4626c4facb1310","name":"WordPress  Download Manager Plugin  < 3.2.62 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-62-contributor-stored-xss-vulnerability","description":"Update the WordPress Download Manager plugin to the latest available version (at least 3.2.62).\nLana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.2.62.","date":"2022-12-20"},{"id":"1f37509c061de800668156f8a25118578d337fd4","name":"Download Manager <= 3.2.61 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3261-authenticated-contributor-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 3.2.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-12-20"},{"id":"856cac0f-2526-4978-acad-d6d82a0bec45","name":"Download Manager &lt; 3.2.62 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/856cac0f-2526-4978-acad-d6d82a0bec45","description":"The plugin does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3d2b7ff37fb7f1c3ed614277065856420ba9909dd5837c75ccf9ff63e9162473","name":"Download Manager [download-manager] < 2.9.97","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.97","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6d7fd8a034d7b0b580fc963fd2ce56fd672504f4","name":"WordPress Download Manager <= 2.9.96 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-2996-cross-site-scripting","description":"The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2019-06-16"}],"impact":[]},{"uuid":"66d2f6f5c03b2306723debe349a40bce98a6bc158eff1903005d67e6f1981827","name":"Download Manager [download-manager] < 2.9.61","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.61","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c7624b475fdc9965e4feb7e8aeb5f8eedf454fcc","name":"WordPress Download Manager <= 2.9.6 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-296-cross-site-request-forgery","description":"The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for unauthenticated attackers to install malicious plugins and\/or packages via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2018-01-09"}],"impact":[]},{"uuid":"1b72a3d9bab584393f52403a9c3c8c5706f1ebbde8d08218eeb8f06dbea7bb54","name":"Download Manager [download-manager] < 2.9.46","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.46","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8bf7dc0b13ac87ac6d84b97aa69a69fa26e9a8c5","name":"WordPress Download Manager <= 2.9.45 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-2945-cross-site-request-forgery","description":"The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it possible for unauthenticated attackers to modify administrative settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2017-03-01"}],"impact":[]},{"uuid":"475b5f502bdc7e01bdf40787805441f45135d7232f071204a075e3d003676855","name":"Download Manager [download-manager] < 2.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1409f1212928d045f22001ff52b340f183d13670","name":"Download Manager <= 2.8.7 - Sensitive Information Disclosure via Directory Listing","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-287-sensitive-information-disclosure-via-directory-listing","description":"The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers to read all of the files listed in that directory.","date":"2016-01-19"}],"impact":[]},{"uuid":"d264deebffdea37e718d7231ca96f849ba77cb748591e5c293d3d123e0db5812","name":"Download Manager [download-manager] < 2.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"31742cfb2965f38502dac33371b153129846889a","name":"Download Manager <= 2.8.7 - Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-287-privilege-escalation","description":"The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.","date":"2016-01-19"}],"impact":[]},{"uuid":"64be22da571f6ec70d06b27ecb13030324dd62df4754002f154e69f639e7bbbe","name":"Download Manager [download-manager] < 2.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e4733db3755ac8693f863fc176843c66bf34b8e3","name":"Download Manager <= 2.8.7 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-287-missing-authorization","description":"The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary files with posts and subsequently download those files causing sensitive information disclosure.","date":"2016-01-19"}],"impact":[]},{"uuid":"97477181ca0f3e94e452e483e51f6504c9fd6dff23f987d122fe292b14d16a03","name":"Download Manager [download-manager] < 2.7.95","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.95","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a2169e8d1c00cb0652611da65e6d3eed775cc5c0","name":"WordPress Download Manager <= 2.7.94 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-2794-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2015-07-16"}],"impact":[]},{"uuid":"0bc8006550036d95791d561820baa973887062396a80b4a1effeb26bce49d110","name":"Download Manager [download-manager] < 2.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6a91e3f815451e2e78fe37ca7dd66491b9289998","name":"WordPress Download Manager <= 2.7.4 - Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/wordpress-download-manager-274-remote-code-execution","description":"The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.","date":"2014-12-15"}],"impact":[]},{"uuid":"3e745f866d878a4a6f567edd33bddc6fdf43eb0f8e4812c46e3f44c4153da36d","name":"Download Manager [download-manager] < 2.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"08495341a9e6640a1aacf0b99715dcfd0953bd70","name":"Download Manager <= 2.2.2 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-222-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2014-08-01"}],"impact":[]},{"uuid":"7aea2f1506586cb9edbbd1807f335efb2feef685dcd6cbc74fc1477dee36a29b","name":"Download Manager [download-manager] < 2.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f3f46b154001f285c6e191f079b8effcaa304bac","name":"Download Manager <= 2.5.8 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-258-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2013-12-07"}],"impact":[]},{"uuid":"3bfb2b34059bc72b7ec35f50ba26da9cd1cdd6e99fea5baac00d477e8cecb78f","name":"Download Manager [download-manager] < 3.2.71","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.71","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2305","name":"CVE-2023-2305","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2305","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-06-09"},{"id":"baada33907e6cce00ffb36ecf9b9b42be4a59105","name":"Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3270-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-05-12"},{"id":"2b77d5bedbb0f11dd0e2becf006916823bd77861","name":"WordPress  Download Manager Plugin  <= 3.2.70 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-70-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress Download Manager plugin to the latest available version (at least 3.2.71).\nLana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.2.71.","date":"2023-05-15"},{"id":"a2813655-91d3-49ec-acc3-69b2c8f81631","name":"Download Manager &lt; 3.2.71 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/a2813655-91d3-49ec-acc3-69b2c8f81631","description":"The plugin does not properly sanitize and escape user-supplied attributes in &#039;wpdm_members&#039;, &#039;wpdm_login_form&#039;, and &#039;wpdm_reg_form&#039; shortcodes, leading to Stored Cross-Site Scripting vulnerabilities.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"50edd774206ec5de40bd14e12c02a389fe15cb930f0bc2e44488bf1af5e24f12","name":"Download Manager [download-manager] < 3.2.71","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.71","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1524","name":"CVE-2023-1524","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1524","description":"[en] The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.","date":"2023-05-30"},{"id":"42095fbb7aa1f7fec9b60ea9721c3f1194d5d28d","name":"WordPress  Download Manager Plugin  < 3.2.71 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-71-broken-access-controls-vulnerability","description":"Update the WordPress Download Manager plugin to the latest available version (at least 3.2.71).\nJohan Kragt discovered and reported this Broken Access Control vulnerability in WordPress Download Manager Plugin.  This vulnerability has been fixed in version 3.2.71.","date":"2023-05-30"},{"id":"d8cb95f6b88e524d5fcd004ff76aa257742d1603","name":"Download Manager <= 3.2.70 - Insufficient Authorization to Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3270-insufficient-authorization-to-information-disclosure","description":"The Download Manager plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.2.7.0, due to insufficient validation of passwords on password protected files. This makes it possible for authenticated attackers, with access to the downloads area to create a password protected post which returns a master key, and then subsequently use that master key and original password to access any other password protected post.","date":"2023-05-08"},{"id":"3802d15d-9bfd-4762-ab8a-04475451868e","name":"Download Manager &lt; 3.2.71 - Broken Access Controls","link":"https:\/\/wpscan.com\/vulnerability\/3802d15d-9bfd-4762-ab8a-04475451868e","description":"The plugin does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file&#039;s password.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"afd5079707e8a9a155e712793f5f70df178aff981029afabb3f44dac67f00571","name":"Download Manager [download-manager] < 3.2.83","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.83","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6421","name":"CVE-2023-6421","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6421","description":"[en] The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.","date":"2024-01-01"},{"id":"244c7c00-fc8d-4a73-bbe0-7865c621d410","name":"Download Manager &lt; 3.2.83 - Unauthenticated Protected File Download Password Leak","link":"https:\/\/wpscan.com\/vulnerability\/244c7c00-fc8d-4a73-bbe0-7865c621d410","description":"The plugin does not protect file download&#039;s passwords, leaking it upon receiving an invalid one.","date":null},{"id":"fecf28506c1b63950c01016bda536b0357acf4eb","name":"Download Manager <= 3.2.82 - Unauthenticated Password Leak","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3282-unauthenticated-password-leak","description":"The Download Manager plugin for WordPress is vulnerable to information Exposure in all versions up to, and including, 3.2.82. This is due to the plugin leaking the password to a protected file when it receives an invalid password. This makes it possible for unauthenticated attackers to gain access to protected files.","date":"2023-11-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-522","name":"Insufficiently Protected Credentials","description":"The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and\/or retrieval."},{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d7812ffc024e1e21e06a95c9ee7684bf9ee2827ed27add859a7053a08735d293","name":"Download Manager [download-manager] < 3.2.85","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.85","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6785","name":"CVE-2023-6785","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6785","description":"[en] The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).","date":"2024-03-13"},{"id":"4d5b99a2eca161a1618708651018b3cb98288bb7","name":"Download Manager <= 3.2.84 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3284-missing-authorization","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).","date":"2024-02-28"},{"id":"9ff1be3a7c6678e9c14f43b95529448be69d4e68","name":"WordPress  Download Manager Plugin    <= 3.2.84 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-84-missing-authorization-vulnerability","description":"Update the WordPress Download Manager plugin to the latest available version (at least 3.2.85).\nwesley (wcraft) discovered and reported this Broken Access Control vulnerability in WordPress Download Manager Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.2.85.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"aca8c687-2378-4447-b311-c2547076e4fd","name":"Download Manager &lt; 3.2.85 - Unauthenticated File Download","link":"https:\/\/wpscan.com\/vulnerability\/aca8c687-2378-4447-b311-c2547076e4fd","description":"The plugin is vulnerable to unauthorized file download of files added via the plugin, allowing unauthenticated attackers to download files added with the plugin (even when privately published).","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8933f44044a1daf73ee23cf05c19bc1a24954b64b62938666229ae8414ad1730","name":"Download Manager [download-manager] < 3.2.86","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.86","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6954","name":"CVE-2023-6954","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6954","description":"[en] The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-13"},{"id":"4ed74190a7f13c3e78466a03b73f26603e65e314","name":"Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3285-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-28"},{"id":"a20dbd4bd7c831fc68afaf64f4612f5bce8e4d93","name":"WordPress  Download Manager Plugin    <= 3.2.85 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-85-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress Download Manager plugin to the latest available version (at least 3.2.86).\nRichard Telleng (stueotue) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.2.86.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"f39b368c-f1b7-4d9c-9dd9-2aa2bc81f1a8","name":"Download Manager &lt; 3.2.86 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/f39b368c-f1b7-4d9c-9dd9-2aa2bc81f1a8","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5c3ed4fbbca7ef812e01e503ce9f0a261005730d178b2239e4300e06767bcb66","name":"Download Manager [download-manager] < 3.2.85","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.85","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-29114","name":"CVE-2024-29114","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-29114","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n\/a through 3.2.84.","date":"2024-03-19"},{"id":"687919781195ec520be66ee16c379e9e518ffa9b","name":"WordPress  Download Manager Plugin    <= 3.2.84 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-84-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Download Manager plugin to the latest available version (at least 3.2.85).\nLVT-tholv2k discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.2.85.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"6fc150add02fbfcbf70873895fd44c8932b6ed8a","name":"Download Manager <= 3.2.84 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager-2\/download-manager-3284-authenticated-contributor-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-16"},{"id":"8f1c8ee3-2365-4a09-a039-222da238db5f","name":"Download Manager &lt; 3.2.85 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/8f1c8ee3-2365-4a09-a039-222da238db5f","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4be3994a16e0d6d0d90bb0a2e4da55387fa7e6bb0bea696cbbba36aea1be2656","name":"Download Manager [download-manager] < 3.2.83","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.83","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-32131","name":"CVE-2024-32131","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-32131","description":"[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n\/a through 3.2.82.","date":"2024-05-17"},{"id":"1ff6698c0a460d030aac55a7f637f2d486a4ec66","name":"WordPress  Download Manager Plugin    <= 3.2.82 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-82-file-password-lock-bypass-vulnerability","description":"No patched version is available. No reply from the vendor since Nov 15, 2023. We have notified the WP plugins review team.\nLiu Shaohong discovered and reported this Bypass Vulnerability vulnerability in WordPress Download Manager Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has not been known to be fixed yet.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"aad1e477bf72be264cea2f2c496875a75445ee45","name":"Download Manager <= 3.2.82 - Password Protected File Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/downloadmanager\/download-manager-3282-password-protected-file-bypass","description":"The Download Manager plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.2.82. This makes it possible for unauthenticated attackers to bypass password protected file restrictions","date":"2024-04-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bac60012787503bb55e53eaea23cffb52ed40a279711f625d7d4c9b64b380f12","name":"Download Manager [download-manager] < 3.2.91","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.91","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4160","name":"CVE-2024-4160","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4160","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-31"},{"id":"e5b49dcc98606ebe54c240f0d2ee5135bac81dd7","name":"WordPress Download Manager Plugin <= 3.2.90 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-90-authenticated-contributor-stored-cross-site-scripting-via-wpdm-all-packages-shortcode-vulnerability","description":"<p>WordPress Download Manager Plugin <= 3.2.90 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Download Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/download-manager\/#developers<\/p><p>Affected Version <= 3.2.90<\/p><p>Fixed in version 3.2.91 <\/p>","date":"2024-05-31"},{"id":"0b43d1ec042e655d7b6c1dc5068d225f09625474","name":"Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3290-authenticated-contributor-stored-cross-site-scripting-via-wpdm-all-packages-shortcode","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8a12d021e0f2178b83279c736eb9ad5b6059f18215cd1c1b0c2d1381ee7ec461","name":"Download Manager [download-manager] < 3.2.94","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.94","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4001","name":"CVE-2024-4001","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4001","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-05"},{"id":"05713efecd16c9eeece3e1596618171c37a922a5","name":"Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3293-authenticated-contributor-stored-cross-site-scripting-via-wpdm-modal-login-form-shortcode","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-04"},{"id":"ce4c478216a4278a166082984f1e482b81d21995","name":"WordPress Download Manager Plugin <= 3.2.93 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-93-authenticated-contributor-stored-cross-site-scripting-via-wpdm-modal-login-form-shortcode-vulnerability","description":"<p>WordPress Download Manager Plugin <= 3.2.93 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Download Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/download-manager\/#developers<\/p><p>Affected Version <= 3.2.93<\/p><p>Fixed in version 3.2.94 <\/p>","date":"2024-06-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3ecb22e261d59fade8de868fe3f12662d1b4a5be8a46bf82cb88190fe25c5feb","name":"Download Manager [download-manager] < 3.2.94","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.94","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5266","name":"CVE-2024-5266","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5266","description":"[en] The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-12"},{"id":"6a883b1e1f22f7dda8b628052ad0716aa3836c1d","name":"Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3292-authenticated-author-stored-cross-site-scripting-via-multiple-shortcodes","description":"The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-11"},{"id":"0cc37fbf2797b380eb7a7cf265862378ea3ac631","name":"WordPress Download Manager Plugin <= 3.2.92 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-92-authenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Download Manager Plugin <= 3.2.92 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Download Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/download-manager\/#developers<\/p><p>Affected Version <= 3.2.92<\/p><p>Fixed in version 3.2.94 <\/p>","date":"2024-06-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c1ed6ff6bd45cf8d46c5a027234f3502d3df929a0740d58bd9f309f9a02fe86a","name":"Download Manager [download-manager] < 3.2.87","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.87","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1766","name":"CVE-2024-1766","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1766","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.","date":"2024-06-12"},{"id":"bbe7d9d69b8971d9a79798496307832720237d64","name":"Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3286-authenticated-subscriber-stored-self-based-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.","date":"2024-06-11"},{"id":"5aeaf7ae48229469c538516091e2825a2bd8cd5c","name":"WordPress Download Manager Plugin <= 3.2.86 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-86-authenticated-subscriber-stored-self-based-cross-site-scripting-vulnerability","description":"<p>WordPress Download Manager Plugin <= 3.2.86 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Download Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/download-manager\/#developers<\/p><p>Affected Version <= 3.2.86<\/p><p>Fixed in version 3.2.87 <\/p>","date":"2024-06-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"35822d4e29399b98bf3dc9fd6795891302c27e440e4676315ced52abb7f87cd1","name":"Download Manager [download-manager] < 3.2.90","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.90","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2098","name":"CVE-2024-2098","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2098","description":"[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.","date":"2024-06-13"},{"id":"c6dbc5cd93da1127e66c3917b81043a71abd55d0","name":"WordPress Download Manager Plugin <= 3.2.89 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-89-improper-authorization-via-protectmedialibrary-vulnerability","description":"<p>WordPress Download Manager Plugin <= 3.2.89 is vulnerable to Broken Access Control<\/p><p>Software: Download Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/download-manager\/#developers<\/p><p>Affected Version <= 3.2.89<\/p><p>Fixed in version 3.2.90 <\/p>","date":"2024-06-12"},{"id":"4976a72eeacfdd8a123cd717eb35e8693277c6fb","name":"Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3289-improper-authorization-via-protectmedialibrary","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.","date":"2024-06-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-289","name":"Authentication Bypass by Alternate Name","description":"The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor."},{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"247539e13a263c8bd36e97a17ec0aac695dc3a47234de0b380a0f34bc549e87d","name":"Download Manager [download-manager] < 3.2.98","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.98","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6208","name":"CVE-2024-6208","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6208","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-07-31"},{"id":"35123cd537b684761d9fdc9bdf5e6c2460092fe5","name":"Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3297-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-07-30"},{"id":"1b2de04a647f99ef0947e3ff328ce2336d3eea1b","name":"WordPress Download Manager Plugin <= 3.2.97 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-2-97-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"<p>WordPress Download Manager Plugin <= 3.2.97 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Download Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/download-manager\/#developers<\/p><p>Affected Version <= 3.2.97<\/p><p>Fixed in version 3.2.98 <\/p>","date":"2024-07-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9a262b0f992028cd36ec2c833cc5d30c0a340f4b37b75d4d0ed980fa877b074b","name":"Download Manager [download-manager] < 3.2.99","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.99","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8284","name":"Download Manager <= 3.2.98 - Admin+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8284","description":"The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed","date":"0000-00-00"},{"id":"fe9944403ddebe3662ae99d3ba138c5b8fa78fe2","name":"Download Manager <= 3.2.98 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3298-authenticated-admin-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.98 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-09-23"},{"id":"EUVD-2025-15266","name":"EUVD-2025-15266","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15266","description":"The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed","date":"2025-05-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"2a764468308cc19b045cae0907bde99229515782ac743707bf5a141e5bda726f","name":"Download Manager [download-manager] < 3.3.00","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.00","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8444","name":"CVE-2024-8444","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8444","description":"[en] The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.","date":"2024-10-30"},{"id":"8863ab334ee1e3f6ec81ad92e49395525dfeeab4","name":"WordPress Download Manager Plugin < 3.3.00 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-3-00-contributor-stored-xss-vulnerability","description":"<p>WordPress Download Manager Plugin < 3.3.00 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Download Manager<\/p><p>Link: https:\/\/wordpress.org\/plugins\/download-manager\/#developers<\/p><p>Affected Version < 3.3.00<\/p><p>Fixed in version 3.3.00 <\/p>","date":"2024-10-30"},{"id":"7e1594cfa5566dac356baae5958bc33fd391918e","name":"Download Manager <= 3.2.99 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3299-authenticated-contributor-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_login_form' shortcode in all versions up to, and including, 3.2.99 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-10-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1fa34985a6f70de871005aece867147bf4d8e964394025a44bd9380997b319ef","name":"Download Manager [download-manager] < 3.3.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-11740","name":"CVE-2024-11740","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-11740","description":"[en] The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","date":"2024-12-19"},{"id":"2a24d585397cfb6d4979c95785516ecb728326dc","name":"Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3303-unauthenticated-arbitrary-shortcode-execution","description":"The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","date":"2024-12-18"},{"id":"c40fe886ca73fe82fb9de3e17a2eb561a0787036","name":"WordPress Download Manager Plugin <= 3.3.03 is vulnerable to Arbitrary Code Execution","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/download-manager\/vulnerability\/wordpress-download-manager-plugin-3-3-03-unauthenticated-arbitrary-shortcode-execution-vulnerability","description":"<p>WordPress Download Manager Plugin <= 3.3.03 is vulnerable to Arbitrary Code Execution<\/p><p>Software: Download Manager<\/p><p>Fixed in version 3.3.04 <\/p><p>Affected Version <= 3.3.03<\/p><p>CVE: CVE-2024-11740<\/p>","date":"2024-12-18"},{"id":"EUVD-2024-33968","name":"EUVD-2024-33968","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-33968","description":"The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.","date":"2024-12-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"7.3","severity":"h","exploitable":"3.9","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"7.3","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"3.9","impact":"3.4"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.040"}},{"uuid":"af659bf7889f5376d3a2f990c0b7fe384f4ab0868009ba2190cae79f2790eaed","name":"Download Manager [download-manager] < 3.3.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-11768","name":"CVE-2024-11768","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-11768","description":"[en] The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.","date":"2024-12-19"},{"id":"abc1a5b751fac7f3b39caf32cbc15c8c5e55d8e2","name":"Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3303-improper-authorization-to-unauthenticated-download-of-password-protected-files","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.","date":"2024-12-18"},{"id":"EUVD-2024-33793","name":"EUVD-2024-33793","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-33793","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.","date":"2024-12-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-285","name":"Improper Authorization","description":"The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"0cd9189c696c8730fa82918e32031cd28068c1172286e96bbfe50c56047519d0","name":"Download Manager [download-manager] < 3.3.03","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.03","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10706","name":"CVE-2024-10706","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10706","description":"[en] The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2024-12-20"},{"id":"24a1c6f3b57e63e88526a32ec37d702bceea197c","name":"Download Manager <= 3.3.02 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3302-authenticated-admin-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.02 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-11-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6a1a62155be5fb7d170c19f4c7bd13b6130580e292b0785ed3b2161789bfd4e6","name":"Download Manager [download-manager] < 3.3.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-56217","name":"CVE-2024-56217","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-56217","description":"[en] Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n\/a through <= 3.3.03.","date":"2024-12-31"},{"id":"c35613417c482062ca2a74e7e8d359bbc6562281","name":"Download Manager <= 3.3.03 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3303-missing-authorization","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.03. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.","date":"2024-12-19"},{"id":"EUVD-2024-53015","name":"EUVD-2024-53015","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-53015","description":"Missing Authorization vulnerability in W3 Eden, Inc. Download Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n\/a through 3.3.03.","date":"2024-12-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"4.3","severity":"m","exploitable":"2.8","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"2.8","impact":"3.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"e45136bbd61d9e6e84ad54d82c3f5aa7a6232d44074506de05842ae0d3508f70","name":"Download Manager [download-manager] < 3.3.09","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.09","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-1785","name":"Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-1785","description":"The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.","date":"0000-00-00"},{"id":"32f27c4c44e6928fb58d5d73991f63f32c023f8e","name":"Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3308-authenticated-author-path-traversal-to-limited-file-overwrite","description":"The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.","date":"2025-03-12"},{"id":"EUVD-2025-6256","name":"EUVD-2025-6256","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-6256","description":"The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.","date":"2025-03-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"2.8","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"high","exploitable":"2.8","impact":"5.2"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.008"}},{"uuid":"e0625be0ac1005f474d67a0fc4b6d3fc2cfbd5db7623ccc71a97921e62428ff2","name":"Download Manager [download-manager] < 3.3.07","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.07","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-13126","name":"CVE-2024-13126","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13126","description":"[en] The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.","date":"2025-03-16"},{"id":"EUVD-2025-6518","name":"EUVD-2025-6518","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-6518","description":"The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.","date":"2025-03-16"},{"id":"212e83ca500c4173348796d5cce73702b6d0be1f","name":"Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3306-unauthenticated-information-disclosure-via-unprotected-directory","description":"The Download Manager plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 3.3.06. This is due to plugin not providing any access restrictions to the direct in which download files are uploaded. This makes it possible for unauthenticated attackers to access downloads that should be password protected by downloading them straight from the directory.","date":"2025-01-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:R\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"h","pr":"l","ui":"r","s":"u","c":"l","i":"l","a":"l","score":"4.6","severity":"m","exploitable":"1.2","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:R\/S:U\/C:L\/I:L\/A:L","score":"4.6","severity":"medium","av":"network","ac":"high","pr":"low","ui":"required","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"1.2","impact":"3.4"},"cwe":[{"cwe":"CWE-552","name":"Files or Directories Accessible to External Parties","description":"The product makes files or directories accessible to unauthorized actors, even though they should not be."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.005"}},{"uuid":"e5709fa3a90cf45517d31c3b28f7b8b79f376af984c880f18969441ee5268403","name":"Download Manager [download-manager] < 3.3.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3056","name":"Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3056","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","date":"0000-00-00"},{"id":"b59f601f119cea3e7c142dd7f200431e8710b24c","name":"Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3312-authenticated-author-stored-cross-site-scripting-via-svg-file-upload","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","date":"2025-04-17"},{"id":"EUVD-2025-11832","name":"EUVD-2025-11832","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-11832","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","date":"2025-04-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"56e75200e8aca0fd28fb6278817c0c4b6c42cb8794ce52fc04b79deffcba91a6","name":"Download Manager [download-manager] < 3.3.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3404","name":"Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3404","description":"The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).","date":"0000-00-00"},{"id":"d4e166123cde61e33b669851a89cbea304b4f471","name":"Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3312-authenticated-author-arbitrary-file-deletion","description":"The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).","date":"2025-04-18"},{"id":"EUVD-2025-15051","name":"EUVD-2025-15051","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15051","description":"The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).","date":"2025-04-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.003"}},{"uuid":"1374c6f52cdc306fd0e44f304b3d325bf55e80747c7f8d761795ee46baeab9b3","name":"Download Manager [download-manager] < 3.3.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4367","name":"Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4367","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"23f0587c119566472c5fbe22229e8b58f656e325","name":"Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3318-authenticated-author-stored-cross-site-scripting-via-wpdm-user-dashboard-shortcode","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-18"},{"id":"EUVD-2025-18680","name":"EUVD-2025-18680","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-18680","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b3ee9ff281ebad0de3e81586612bdb020c37a2e85b304199526c3aaed62b6bb7","name":"Download Manager [download-manager] < 3.3.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-60093","name":"CVE-2025-60093","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-60093","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager allows Cross Site Request Forgery. This issue affects Download Manager: from n\/a through 3.3.24.","date":"2025-09-26"},{"id":"e556ad1fd5b01765ce455c16cab2c9ae5e497591","name":"Download Manager <= 3.3.24 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3324-cross-site-request-forgery","description":"The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-09-26"},{"id":"EUVD-2025-31307","name":"EUVD-2025-31307","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-31307","description":"Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager allows Cross Site Request Forgery. This issue affects Download Manager: from n\/a through 3.3.24.","date":"2025-09-26"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"c375e33880d578f6f1df3e1615a496f0562723d33a9687767cb990f23578f8c1","name":"Download Manager [download-manager] < 3.3.26","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.26","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-60092","name":"CVE-2025-60092","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-60092","description":"[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n\/a through 3.3.24.","date":"2025-09-26"},{"id":"44ce9a75c18d57a526f24a239513fc97af75ba4b","name":"Download Manager <= 3.3.25 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3324-unauthenticated-sensitive-information-exposure","description":"The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2025-09-26"},{"id":"EUVD-2025-31308","name":"EUVD-2025-31308","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-31308","description":"Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n\/a through 3.3.24.","date":"2025-09-26"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-497","name":"Exposure of Sensitive System Information to an Unauthorized Control Sphere","description":"The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":null,"impact":null}}},{"uuid":"2b654ab4f8b58211f0ec124d638af8117141578e18da904280a8cbf8a079559d","name":"Download Manager [download-manager] < 3.3.31","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.31","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-12177","name":"CVE-2025-12177","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-12177","description":"[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.","date":"2025-11-08"},{"id":"85b32e185b6428b981543a5f90f274c1749f972a","name":"Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3330-unauthenticated-cron-trigger-due-to-hardcoded-cron-key","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.","date":"2025-11-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-321","name":"Use of Hard-coded Cryptographic Key","description":"The product uses a hard-coded, unchangeable cryptographic key."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1dcb905812a6bad8998cc04398f6bd2bea42999f9b7c4f32627fa09d80fe16d8","name":"Download Manager [download-manager] < 3.3.33","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.33","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-63070","name":"CVE-2025-63070","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-63070","description":"[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n\/a through <= 3.3.32.","date":"2025-12-09"},{"id":"5316ac7539e6fae8655d7ddf46dd95932b65c159","name":"Download Manager <= 3.3.32 - Authenticated (Subscriber+) Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3332-authenticated-subscriber-information-exposure","description":"The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.","date":"2025-09-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-497","name":"Exposure of Sensitive System Information to an Unauthorized Control Sphere","description":"The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"54dbccaa55a36e6e8f49a49c886218faf306c036bf299b57e21fbddabcd08234","name":"Download Manager [download-manager] < 3.3.33","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.33","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13498","name":"CVE-2025-13498","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13498","description":"[en] The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.","date":"2025-12-18"},{"id":"99c4bc621835e6609705b382574414cbafa70c6d","name":"Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3332-missing-authorization-to-authenticated-subscriber-media-attachment-password-disclosure","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.","date":"2025-12-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9c629a4248fe9cf7ed3b2161c90495bce25e9575367c0382968d4e1a18c612b5","name":"Download Manager [download-manager] < 3.3.41","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.41","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-15364","name":"CVE-2025-15364","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-15364","description":"[en] The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.","date":"2026-01-06"},{"id":"f8041b31c3e694f1e6235d33c300283f803a2093","name":"Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3340-unauthenticated-limited-privilege-escalation-via-updatepassword","description":"The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.","date":"2026-01-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"7.3","severity":"h","exploitable":"3.9","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"7.3","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"3.9","impact":"3.4"},"cwe":[{"cwe":"CWE-353","name":"Missing Support for Integrity Check","description":"The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4356f38f164fc16854d99347a5d0588283b69156a432101c4379f9b7c6558a31","name":"Download Manager [download-manager] < 3.3.54","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.54","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-39615","name":"CVE-2026-39615","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39615","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n\/a through <= 3.3.53.","date":"2026-04-08"},{"id":"8b5ca7a0529d67e0f3a76cb941f2c4345bb1894f","name":"Download Manager <= 3.3.53 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3353-authenticated-author-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-02-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2dc1fcfa7e724ac2d982c37f24eff103cecef94f8f54ab9b0f6c521e2b4b3617","name":"Download Manager [download-manager] < 3.3.53","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.53","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-39676","name":"CVE-2026-39676","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39676","description":"[en] Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n\/a through <= 3.3.52.","date":"2026-04-08"},{"id":"EUVD-2026-20355","name":"EUVD-2026-20355","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-20355","description":"Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n\/a through <= 3.3.52.","date":"2026-04-08"},{"id":"c8a90748be4a90a38c987aa8fd020f8cec728fc4","name":"Download Manager <= 3.3.52 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3352-missing-authorization","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.3.52. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-02-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"044d04166163724a0fb59ba6833334c8edd58c6389c522c3771ee9655aba934b","name":"Download Manager [download-manager] < 3.3.52","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.52","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4057","name":"Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4057","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verifying post ownership via `current_user_can('edit_post', $id)`, and the destructive operations executing before the admin-level check in `mediaAccessControl()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to strip all protection metadata (password, access restrictions, private flag) from any media file they do not own, making admin-protected files publicly accessible via their direct URL.","date":"0000-00-00"},{"id":"ebf714fc438ecd6eea24901c4b74bf91ae328972","name":"Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3351-missing-authorization-to-authenticated-contributor-media-file-protection-removal","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verifying post ownership via `current_user_can('edit_post', $id)`, and the destructive operations executing before the admin-level check in `mediaAccessControl()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to strip all protection metadata (password, access restrictions, private flag) from any media file they do not own, making admin-protected files publicly accessible via their direct URL.","date":"2026-04-09"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"18aa3abd73d2f5c6529f83a1cbb426b8f27b6cadea6bc12d4596d1159ea2049c","name":"Download Manager [download-manager] < 3.3.53","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.53","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5357","name":"Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5357","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is extracted without sanitization in the members() function and stored via update_post_meta(), then echoed directly into an HTML id attribute in the members.php template without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.","date":"0000-00-00"},{"id":"764423f2febc54d50b51cb604527a04346e28357","name":"Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3352-authenticated-contributor-stored-cross-site-scripting-via-shortcode-attributes","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is extracted without sanitization in the members() function and stored via update_post_meta(), then echoed directly into an HTML id attribute in the members.php template without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.","date":"2026-04-08"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7fb99a769dc92978a7d03db8a85571c2a755085912113b54d59c18c605abcd4d","name":"Download Manager [download-manager] < 3.3.50","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.50","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2571","name":"Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2571","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates.","date":"0000-00-00"},{"id":"df291aa2ebee1c491a376d8d7ecb987b4b134357","name":"Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3349-missing-authorization-to-authenticated-subscriber-user-email-enumeration-via-user-parameter","description":"The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates.","date":"2026-03-18"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5248bc7e80ceb034e5e6429596b6adeebe167cf1074473e9f6ffd8cd77303fba","name":"Download Manager [download-manager] < 3.3.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1666","name":"Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1666","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"0000-00-00"},{"id":"90428407c2c045b2e3816d2eb866c89c5ce6c2b8","name":"Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3346-reflected-cross-site-scripting-via-redirect-to-parameter","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2026-02-17"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f997fabbda8317c76a97e40a1e60d00b1884aea874f248d8e694995fd8429668","name":"Download Manager [download-manager] < 3.3.24","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.24","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-10146","name":"Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-10146","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018user_ids\u2019 parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"0000-00-00"},{"id":"bd2d38f9fadda42e15e63ae70974cceb3aedc441","name":"Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3323-reflected-cross-site-scripting-via-user-ids-parameter","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018user_ids\u2019 parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-09-18"},{"id":"EUVD-2025-30233","name":"EUVD-2025-30233","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-30233","description":"The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018user_ids\u2019 parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-09-19"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"ffe1586c711359c5603fd95e2c414b6cc971944b1f6c6004de1788da0265c03c","name":"Download Manager [download-manager] < 3.3.61","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.61","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-13733","name":"CVE-2026-13733","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-13733","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although wp_kses_post is applied to post content on save, it only strips HTML tokens and does not neutralize C-style escape sequences embedded within shortcode attribute values, meaning contributors can craft a payload that survives the kses filter and is silently reconstructed into a raw script tag at render time.","date":"2026-07-01"},{"id":"95c9ffb64bd0a34032335538a5e68b35e6c95d18","name":"Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3360-authenticated-contributor-stored-cross-site-scripting-via-no-data-msg-shortcode-attribute","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although wp_kses_post is applied to post content on save, it only strips HTML tokens and does not neutralize C-style escape sequences embedded within shortcode attribute values, meaning contributors can craft a payload that survives the kses filter and is silently reconstructed into a raw script tag at render time.","date":"2026-06-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fabf81bb94a24f1d4881d44904c85c0e06254ad2090abc60690b0d7829857632","name":"Download Manager [download-manager] < 3.3.62","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.62","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14343","name":"CVE-2026-14343","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14343","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.","date":"2026-07-09"},{"id":"909d1a02ec61e5e22b0cc4b3a09f545eb0d38d09","name":"Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/74cd34be-008c-4ff3-ae3c-417cfd2fee9b","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.","date":"2026-07-08"},{"id":"d38338372ac2dc918fd73a9c6e7aa93c8df8d055","name":"Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3361-authenticated-contributor-stored-cross-site-scripting-via-note-before-and-note-after-shortcode-attributes","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.","date":"2026-06-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"677ebd2b7f1f8794eb8e4acd3578d62cd2b934ca49446b07225cb72ca85ccff3","name":"Download Manager [download-manager] < 3.3.67","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.67","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-16685","name":"CVE-2026-16685","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-16685","description":"[en] The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post() does not neutralize the payload because it operates on post content at save time and does not process shortcode attribute values that are emitted unescaped at render time.","date":"2026-08-01"},{"id":"98f9178710cca53acc236358638211c8954f70de","name":"Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/7a32393e-f233-4ab6-addc-9dd1e04c0e0a","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post() does not neutralize the payload because it operates on post content at save time and does not process shortcode attribute values that are emitted unescaped at render time.","date":"2026-07-31"},{"id":"85b87b8aa7639093e617a37ef2a4ca4dd6879451","name":"Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3366-authenticated-contributor-stored-cross-site-scripting-via-icon-shortcode-attribute","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post() does not neutralize the payload because it operates on post content at save time and does not process shortcode attribute values that are emitted unescaped at render time.","date":"2026-07-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e9fcb2503893dc63934379a7cbcc734fec97f6b0f827e782f418d91e045dc76c","name":"Download Manager [download-manager] < 3.3.66","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.66","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-14292","name":"CVE-2026-14292","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-14292","description":"[en] The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.","date":"2026-08-01"},{"id":"b5adc05ccf40f2a38bced20c705f55707178c442","name":"Download Manager < 3.3.66 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3366-unauthenticated-stored-cross-site-scripting","description":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-05"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"21c0b2ed76e79cef0dcdc00110667d23ae9df16674d786984a422f1f00e4582a","name":"Download Manager [download-manager] < 3.3.69","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.69","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-92714","name":"CVE-2026-92714","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-92714","description":"[en] The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata \u2014 including protected file references, role-based access restrictions, and password lock settings \u2014 into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files.","date":"2026-09-18"},{"id":"ba8ebdc47e5ce89df833bd2d8771a476ccf0336f","name":"Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-manager\/download-manager-3368-insecure-direct-object-reference-to-authenticated-contributor-sensitive-information-disclosure-via-wpdm-duplicate-parameter","description":"The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata \u2014 including protected file references, role-based access restrictions, and password lock settings \u2014 into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files.","date":"2026-08-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789709630"}