Extension WordPress
Vulnérabilités Download Manager Pro
Cette page rassemble les failles publiées pour Download Manager Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Download Manager Pro
81 fiches
Download Manager <= 3.3.61 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.3.61
3.3.62
08/07/2026
Download Manager <= 3.3.60 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.3.60
3.3.61
30/06/2026
Download Manager <= 3.3.51 – Missing Authorization to Authenticated (Contributor+) Media File Protection Removal
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the…
*-3.3.51
3.3.52
09/04/2026
Download Manager <= 3.3.52 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on…
*-3.3.52
3.3.53
08/04/2026
Download Manager <= 3.3.49 – Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers,…
*-3.3.49
3.3.50
18/03/2026
Download Manager <= 3.3.52 – Missing Authorization
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.3.52. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-3.3.52
3.3.53
19/02/2026
Download Manager <= 3.3.46 – Reflected Cross-Site Scripting via 'redirect_to' Parameter
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET…
*-3.3.46
3.3.47
17/02/2026
Download Manager <= 3.3.53 – Authenticated (Author+) Stored Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…
*-3.3.53
3.3.54
10/02/2026
Download Manager <= 3.3.40 – Unauthenticated Limited Privilege Escalation via updatePassword
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their…
*-3.3.40
3.3.41
05/01/2026
Download Manager <= 3.3.32 – Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes…
*-3.3.32
3.3.33
17/12/2025
Download Manager <= 3.3.30 – Unauthenticated Cron Trigger due to Hardcoded Cron Key
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated…
*-3.3.30
3.3.31
07/11/2025
Download Manager <= 3.3.32 – Authenticated (Subscriber+) Information Exposure
The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration…
*-3.3.32
3.3.33
30/09/2025
Download Manager <= 3.3.24 – Cross-Site Request Forgery
The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-3.3.24
3.3.25
26/09/2025
Download Manager <= 3.3.25 – Unauthenticated Sensitive Information Exposure
The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-3.3.25
3.3.26
26/09/2025
Download Manager <= 3.3.23 – Reflected Cross-Site Scripting via `user_ids` Parameter
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.3.23
3.3.24
18/09/2025
Download Manager <= 3.3.18 – Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-3.3.18
3.3.19
18/06/2025
Download Manager <= 3.3.12 – Authenticated (Author+) Arbitrary File Deletion
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with…
*-3.3.12
3.3.13
18/04/2025
Download Manager <= 3.3.12 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.3.12
3.3.13
17/04/2025
Download Manager <= 3.3.08 – Authenticated (Author+) Path Traversal to Limited File Overwrite
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select…
*-3.3.08
3.3.09
12/03/2025
Download Manager <= 3.3.06 – Unauthenticated Information Disclosure via Unprotected Directory
The Download Manager plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 3.3.06. This is due to plugin not providing any access restrictions to the direct in which download files are uploaded.…
*-3.3.06
3.3.07
17/01/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.