VendorsW3 Edendownload_managerall versions
Vulnerabilities

W3 Eden Download Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2024-11768
Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files
Published 2024-12-19 · Analyzed
5.3EPSS 0.003
CVE-2014-8585
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
Published 2014-11-04 · Modified
5.0EPSS 0.029
CVE-2021-24773
WordPress Download Manager < 3.2.16 - Admin+ Stored Cross-Site Scripting
Published 2021-11-01 · Modified
4.8EPSS 0.029
CVE-2024-8284
Download Manager <= 3.2.98 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003
CVE-2024-10706
Download Manager < 3.3.03 - Admin+ Stored XSS
Published 2024-12-20 · Analyzed
4.8EPSS 0.003
CVE-2024-13126
Download Manager < 3.3.07 - Unauthenticated Data Exposure
Published 2025-03-16 · Analyzed
4.6EPSS 0.005
CVE-2013-7319
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
Published 2014-02-06 · Modified
4.31 PoCEPSS 0.046
CVE-2017-20093
Download Manager Plugin cross-site request forgery
Published 2022-06-24 · Modified
4.3EPSS 0.005
← Prev2 / 2