Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wpdownloadmanager wordpress download manager vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2022-0828
The Download Manager WordPress plugin prior to 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an malicious user to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or passwor...
Wpdownloadmanager Wordpress Download Manager
5.4
CVSSv3
CVE-2023-2305
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output es...
Wpdownloadmanager Wordpress Download Manager
7.5
CVSSv3
CVE-2023-6421
The Download Manager WordPress plugin prior to 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
Wpdownloadmanager Wordpress Download Manager
4.3
CVSSv3
CVE-2017-20093
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
Wpdownloadmanager Wordpress Download Manager 2.8.99
5.4
CVSSv3
CVE-2023-22713
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
Wpdownloadmanager Gutenberg Blocks For Wordpress Download Manager
7.5
CVSSv3
CVE-2023-1809
The Download Manager WordPress plugin prior to 6.3.0 leaks master key information without the need for a password, allowing malicious users to download arbitrary password-protected package files.
Wpdownloadmanager Download Manager
6.1
CVSSv3
CVE-2022-2168
The Download Manager WordPress plugin prior to 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
Wpdownloadmanager Download Manager
8.8
CVSSv3
CVE-2021-25069
The Download Manager WordPress plugin prior to 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
Wpdownloadmanager Download Manager
6.5
CVSSv3
CVE-2023-1524
The Download Manager WordPress plugin prior to 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user ...
Wpdownloadmanager Download Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3