VendorsMetagaussdownload_pluginany version
Vulnerabilities

Metagauss Download Plugin any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-36345
WordPress Download Plugin Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-05-28 · Modified
8.8EPSS 0.003
CVE-2025-6586
Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload
Published 2025-07-04 · Modified
7.2EPSS 0.012
CVE-2024-9829
Download Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download
Published 2024-10-23 · Analyzed
6.5EPSS 0.004
CVE-2021-24703
Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation
Published 2021-11-23 · Modified
5.7EPSS 0.004
CVE-2021-25059
Download Plugin < 2.0.0 - Subscriber+ Website Download
Published 2022-11-28 · Modified
5.4EPSS 0.006