Extension WordPress
Vulnérabilités Download Plugin
Cette page rassemble les failles publiées pour Download Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Download Plugin
5 fiches
Download Plugin <= 2.2.8 – Authenticated (Administrator+) Arbitrary File Upload
The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with…
*-2.2.8
2.2.9
03/07/2025
Download Plugin <= 2.2.0 – Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download
The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for…
*-2.2.0
2.2.1
22/10/2024
Download Plugin <= 2.0.4 – Cross-Site Request Forgery
The Download Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.4. This is due to missing nonce validation on the dpwap_plugin_download_action, dpwap_theme_download, and dpwap_plugin_multiple_download_func functions. This makes it possible for…
[*, 2.0.5)
2.0.5
24/05/2023
Download Plugin <= 1.6.2 – Missing Authorization and Sensitive Information Exposure
The Download Plugin plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.6.2 due to missing capability checks on the dpwap_plugin_multiple_download_func function. This makes it possible for authenticated attackers with subscriber-level attackers to…
*-1.6.2
2.0.0
02/11/2022
Download Plugin < 1.6.1 – Cross-Site Request Forgery
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
[*, 1.6.1)
1.6.1
19/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.