Extension WordPress
Vulnérabilités WP-DownloadManager
Cette page rassemble les failles publiées pour WP-DownloadManager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-DownloadManager
10 fiches
WP-DownloadManager <= 1.69 – Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in the file deletion functionality. This is due to insufficient validation of user-supplied file paths, allowing…
*-1.69
1.69.1
17/02/2026
WP-DownloadManager <= 1.69 – Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal…
*-1.69
1.69.1
17/02/2026
WP-DownloadManager <= 1.68.11 – Authenticated (Admin+) Arbitrary File Upload
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level…
*-1.68.11
1.69
25/09/2025
WP-DownloadManager <= 1.68.10 – Authenticated (Administrator+) Arbitrary File Read
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This…
*-1.68.10
1.68.11
10/06/2025
WP-DownloadManager <= 1.68.10 – Authenticated (Administrator+) Arbitrary File Deletion
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for…
*-1.68.10
1.68.11
10/06/2025
WP-DownloadManager <= 1.68.8 – Reflected Cross-Site Scripting
The WP-DownloadManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.68.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-1.68.8
1.68.9
27/09/2024
WP-DownloadManager plugin <= 1.68.6 – Stored Cross-Site Scripting
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions
[*, 1.68.7)
1.68.7
12/01/2022
WP-DownloadManager <= 1.68.6 – Stored Cross-Site Scripting
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions
[*, 1.68.7)
1.68.7
10/01/2022
WP-DownloadManager plugin <= 1.68.6 – Reflected Cross-Site Scripting
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager WordPress plugin (versions
*-1.68.6
1.68.7
28/12/2021
WP-DownloadManager <= 1.68.4 – Server-Side Request Forgery
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local…
[*, 1.68.5)
1.68.5
13/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.