Extension WordPress

Vulnérabilités Download Plugin

Cette page rassemble les failles publiées pour Download Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Download Plugin

5 fiches

CVE-2024-9829 Moyenne · 6,5
Download Plugin

Download Plugin <= 2.2.0 – Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download

The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for…

Versions affectées

*-2.2.0

Correctif

2.2.1

Publication

22/10/2024

CVE-2022-36345 Moyenne · 4,3
Download Plugin

Download Plugin <= 2.0.4 – Cross-Site Request Forgery

The Download Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.4. This is due to missing nonce validation on the dpwap_plugin_download_action, dpwap_theme_download, and dpwap_plugin_multiple_download_func functions. This makes it possible for…

Versions affectées

[*, 2.0.5)

Correctif

2.0.5

Publication

24/05/2023

CVE-2021-25059 Moyenne · 6,5
Download Plugin

Download Plugin <= 1.6.2 – Missing Authorization and Sensitive Information Exposure

The Download Plugin plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.6.2 due to missing capability checks on the dpwap_plugin_multiple_download_func function. This makes it possible for authenticated attackers with subscriber-level attackers to…

Versions affectées

*-1.6.2

Correctif

2.0.0

Publication

02/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités