VendorsW3 Edendownload_managerall versions
Vulnerabilities

W3 Eden Download Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2014-9260
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
Published 2017-08-07 · Modified
8.81 PoCEPSS 0.111
CVE-2022-2431
Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion
Published 2022-09-06 · Modified
8.8EPSS 0.038
CVE-2022-2436
Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization
Published 2022-09-06 · Modified
8.8EPSS 0.020
CVE-2021-25069
WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSS
Published 2022-02-21 · Analyzed
8.8EPSS 0.015
CVE-2021-34639
WordPress Download Manager <= 3.1.24 Authenticated Arbitrary File Upload
Published 2021-08-05 · Modified
8.8EPSS 0.006
CVE-2022-34347
WordPress Download Manager plugin <= 3.2.48 - Cross-Site Request Forgery (CSRF) vulnerability
Published 2022-08-22 · Modified
8.8EPSS 0.004
CVE-2022-36288
WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
Published 2022-08-23 · Modified
8.8EPSS 0.003
CVE-2025-1785
Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite
Published 2025-03-13 · Analyzed
8.1EPSS 0.007
CVE-2023-6421
Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak
Published 2024-01-01 · Modified
7.5EPSS 0.024
CVE-2022-0828
Download Manager < 3.2.39 - Unauthenticated brute force of files master key
Published 2022-04-11 · Modified
7.5EPSS 0.015
CVE-2021-25087
Wordpress Download Manager < 3.2.25 - Sensitive Information Disclosure
Published 2022-03-07 · Modified
7.5EPSS 0.015
CVE-2022-2362
Download Manager < 3.2.50 - Bypass IP Address Blocking Restriction
Published 2022-08-22 · Modified
7.5EPSS 0.012
CVE-2023-1809
Download Manager Pro < 6.3.0 - Unauthenticated Sensitive Information Disclosure
Published 2023-05-02 · Modified
7.5EPSS 0.007
CVE-2024-2098
Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary
Published 2024-06-13 · Modified
7.5EPSS 0.005
CVE-2024-32131
WordPress Download Manager plugin <= 3.2.82 - File Password Lock Bypass vulnerability
Published 2024-05-17 · Analyzed
7.5EPSS 0.004
CVE-2024-11740
Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution
Published 2024-12-19 · Analyzed
7.3EPSS 0.019
CVE-2021-34638
WordPress Download Manager <= 3.1.24 Authenticated Directory Traversal
Published 2021-08-05 · Modified
6.5EPSS 0.013
CVE-2023-1524
Download Manager < 3.2.71 - Broken Access Controls
Published 2023-05-30 · Analyzed
6.5EPSS 0.007
CVE-2024-29114
WordPress Download Manager plugin <= 3.2.84 - Cross Site Scripting (XSS) vulnerability
Published 2024-03-19 · Modified
6.5EPSS 0.003
CVE-2022-2101
Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting
Published 2022-07-18 · Modified
6.4EPSS 0.011
CVE-2023-2305
Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2023-06-09 · Modified
6.4EPSS 0.006
CVE-2023-6954
Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-03-13 · Modified
6.4EPSS 0.005
CVE-2024-5266
Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes
Published 2024-06-12 · Modified
6.4EPSS 0.004
CVE-2024-6208
Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-07-31 · Analyzed
6.4EPSS 0.004
CVE-2024-4160
Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode
Published 2024-05-31 · Modified
6.4EPSS 0.003
CVE-2025-4367
Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode
Published 2025-06-19 · Analyzed
6.4EPSS 0.002
CVE-2022-45836
WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)
Published 2023-04-18 · Modified
6.3EPSS 0.007
CVE-2024-56217
WordPress Download Manager plugin <= 3.3.03 - Broken Access Control vulnerability
Published 2024-12-31 · Modified
6.3EPSS 0.003
CVE-2019-15889
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
Published 2019-09-03 · Modified
6.11 PoCEPSS 0.114
CVE-2017-2217
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published 2017-07-07 · Modified
6.1EPSS 0.015
CVE-2017-2216
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-07-07 · Modified
6.1EPSS 0.014
CVE-2022-2168
Download Manager < 3.2.44 - Reflected Cross-Site Scripting
Published 2022-07-17 · Analyzed
6.1EPSS 0.014
CVE-2022-1985
Download Manager <= 3.2.42 - Reflected Cross-Site Scripting
Published 2022-06-13 · Modified
6.1EPSS 0.012
CVE-2017-18032
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
Published 2018-01-16 · Modified
6.1EPSS 0.009
CVE-2021-24969
Download Manager < 3.2.22 - Subscriber+ Stored Cross-Site Scripting
Published 2021-12-27 · Modified
5.4EPSS 0.006
CVE-2022-4476
Download Manager < 3.2.62 - Contributor+ Stored XSS
Published 2023-01-16 · Modified
5.4EPSS 0.006
CVE-2022-34658
WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
Published 2022-08-23 · Modified
5.4EPSS 0.006
CVE-2024-1766
Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting
Published 2024-06-12 · Modified
5.4EPSS 0.003
CVE-2024-8444
Download Manager < 3.3.00 - Contributor+ Stored XSS
Published 2024-10-30 · Analyzed
5.4EPSS 0.003
CVE-2023-6785
Download Manager <= 3.2.84 - Missing Authorization
Published 2024-03-13 · Modified
5.3EPSS 0.005
1 / 2Next →