VendorsWP-DownloadManager Projectwp-downloadmanagerall versions
Vulnerabilities

WP-DownloadManager Project WP-DownloadManager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-4799
WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Deletion
Published 2025-06-11 · Analyzed
7.2EPSS 0.009
CVE-2022-25606
WordPress WP-DownloadManager plugin <= 1.68.5 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
Published 2022-03-25 · Modified
5.4EPSS 0.006
CVE-2022-25605
WordPress WP-DownloadManager plugin <= 1.68.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
Published 2022-03-18 · Modified
5.4EPSS 0.006
CVE-2021-44760
WordPress WP-DownloadManager plugin <= 1.68.6 - Auth. Reflected Cross-Site Scripting (XSS) vulnerability
Published 2022-03-18 · Modified
5.4EPSS 0.005
CVE-2020-24141
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
Published 2021-07-07 · Modified
5.3EPSS 0.009
CVE-2025-4798
WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Read
Published 2025-06-11 · Analyzed
4.9EPSS 0.004