Extension WordPress
Vulnérabilités Download Manager Pro, page 3
Cette page rassemble les failles publiées pour Download Manager Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Download Manager Pro
81 fiches
Download Manager <= 3.2.59 – Refleced Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘packages-shortcode-toolbar.php’, 'Shortcodes.php', and 'category-shortcode-toolbar.php' (in both 'src/Package/views/' and 'src/Category/views/') files in versions up to, and including, 3.2.59 due to insufficient input sanitization and output…
*-3.2.59
3.2.60
29/11/2022
Download Manager <= 3.2.54 – Authenticated (Admin+) Path Traversal
The Download Manager plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.2.54 via the File Browser Root field. This makes it possible for administrator-level attackers to list and read arbitrary files and…
[*, 3.2.55)
3.2.55
05/09/2022
Download Manager <= 3.2.49 – Authenticated (Contributor+) PHAR Deserialization
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call…
*-3.2.49
3.2.50
17/08/2022
Download Manager <= 3.2.53 – Reflected Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it…
*-3.2.53
3.2.54
04/08/2022
Download Manager <= 3.2.48 – Cross-Site Request Forgery
The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete stats…
*-3.2.48
3.2.49
02/08/2022
Download Manager <= 3.2.48 – Cross-Site Request Forgery to Plugin Settings Update
The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation on the updateTemplateStatus function. This makes it possible for unauthenticated…
*-3.2.48
3.2.49
02/08/2022
Download Manager <= 3.2.49 – IP Blocking Bypass
The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 due to the way the visitor's IP address is determined. This allows an unauthenticated attacker to spoof their IP…
*-3.2.49
3.2.50
01/08/2022
Download Manager <= 3.2.50 – Authenticated (Contributor+) Arbitrary File Deletion
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file…
*-3.2.50
3.2.51
27/07/2022
Download Manager <= 3.2.48 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ and 'label' parameters in versions up to, and including, 3.2.48 due to insufficient input sanitization and output escaping when setting lock options for…
*-3.2.48
3.2.49
06/07/2022
Download Manager <= 3.2.43 – Reflected Cross-Site Scripting
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
*-3.2.43
3.2.44
27/06/2022
Download Manager <= 3.2.43 – Reflected Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject…
*-3.2.43
3.2.44
23/06/2022
Download Manager <= 3.2.46 – Contributor+ Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…
*-3.2.46
3.2.47
21/06/2022
Download Manager <= 3.2.42 – Reflected Cross-Site Scripting
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
*-3.2.42
3.2.43
02/06/2022
Download Manager <= 3.2.38 – Unauthenticated Brute Force of File Master Key
The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role…
[*, 3.2.39)
3.2.39
16/03/2022
Download Manager <= 3.2.34 – Sensitive Information Disclosure
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed…
[*, 3.2.35)
3.2.35
02/02/2022
WordPress Download Manager <= 3.2.33 – Authenticated SQL Injection
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting…
[*, 3.2.34)
3.2.34
20/01/2022
WordPress Download Manager <= 3.2.21 – Cross-Site Scripting
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the…
[*, 3.2.22)
3.2.22
29/11/2021
WordPress Download Manager <= 3.2.15 – Cross-Site Scripting
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed
[*, 3.2.16)
3.2.16
29/09/2021
WordPress Download Manager <= 3.2.12 – Cross-Site Request Forgery
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for…
[*, 3.2.13)
3.2.13
09/08/2021
WordPress Download Manager <= 3.1.24 – Cross-Site Scripting
Authenticated Directory Traversal in WordPress Download Manager
*-3.1.24
3.1.25
29/07/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.