Extension WordPress
Vulnérabilités Download Manager Pro, page 4
Cette page rassemble les failles publiées pour Download Manager Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Download Manager Pro
81 fiches
WordPress Download Manager <= 3.1.24 – Authenticated File Upload
Authenticated File Upload in WordPress Download Manager
*-3.1.24
3.1.25
29/07/2021
WordPress Download Manager < 3.1.19 – Arbitrary File Upload
The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it…
[*, 3.1.19)
3.1.19
30/04/2021
WordPress Download Manager < 3.1.23 – Arbitrary Asset Manager Usage
The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers…
[*, 3.1.23)
3.1.23
30/04/2021
WordPress Download Manager < 3.1.22 – Cross-Site Request Forgery
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated…
[*, 3.1.22)
3.1.22
30/04/2021
Download Manager <= 3.1.17 – Missing Authorization
The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for…
[*, 3.1.18)
3.1.18
16/04/2021
WordPress Download Manager <= 2.9.96 – Cross-Site Scripting
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
[*, 2.9.97)
2.9.97
16/06/2019
WordPress Download Manager <= 2.9.93 – Cross-Site Scripting
The WordPress Download Manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
[*, 2.9.94)
2.9.94
13/04/2019
WordPress Download Manager <= 2.9.6 – Cross-Site Request Forgery
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for…
*-2.9.6
2.9.61
09/01/2018
WordPress Download Manager < 2.9.51 – Open Redirect
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
[*, 2.9.51)
2.9.51
13/07/2017
WordPress Download Manager <= 2.9.51 – Cross-Site Scripting
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
*-2.9.51
2.9.52
16/06/2017
WordPress Download Manager <= 2.9.49 – Reflected Cross-Site Scripting
The WordPress Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in versions up to, and including, 2.9.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 2.9.50)
2.9.50
13/06/2017
WordPress Download Manager <= 2.9.45 – Cross-Site Request Forgery
The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it…
*-2.9.45
2.9.46
01/03/2017
Download Manager <= 2.8.7 – Missing Authorization
The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary…
[*, 2.8.8)
2.8.8
19/01/2016
Download Manager <= 2.8.7 – Privilege Escalation
The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions…
[*, 2.8.8)
2.8.8
19/01/2016
Download Manager <= 2.8.7 – Sensitive Information Disclosure via Directory Listing
The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers…
[*, 2.8.8)
2.8.8
19/01/2016
WordPress Download Manager <= 2.7.94 – Stored Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it…
*-2.7.94
2.7.95
16/07/2015
WordPress Download Manager <= 2.7.4 – Remote Code Execution
The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.
[*, 2.7.5)
2.7.5
15/12/2014
WordPress Download Manager <= 2.7.2 – Authenticated Arbitrary Options Update
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
[*, 2.7.3)
2.7.3
24/11/2014
Download Manager <= 2.2.2 – Cross-Site Scripting
The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.2.2
2.2.3
01/08/2014
Download Manager < 2.5.9 – Stored Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
*-2.5.8
2.5.9
08/12/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.