WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Download Manager?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Download Manager — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: download-manager
  • 100000+ instalaciones activas

digital storedocument managementdownload managerecommercefile manager

Estado de mantenimiento

  • Última versión conocida: 3.3.66
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

64 CVEs conocidos registrados para Download Manager.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-14343 Download Manager [download-manager] < 3.3.62 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.3.62 3.3.62 2026-07-08 ✓ corregido en la última versión
CVE-2026-13733 Download Manager [download-manager] < 3.3.61 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.3.61 3.3.61 2026-06-30 ✓ corregido en la última versión
CVE-2026-39676 Download Manager [download-manager] < 3.3.53 Media 5,3 < 3.3.53 3.3.53 2026-02-19 ✓ corregido en la última versión
CVE-2026-39615 Download Manager [download-manager] < 3.3.54 Media 5,9 < 3.3.54 3.3.54 2026-02-10 ✓ corregido en la última versión
CVE-2025-15364 Download Manager [download-manager] < 3.3.41 Falta de soporte para verificación de integridad Alta 7,3 < 3.3.41 3.3.41 2026-01-05 ✓ corregido en la última versión
CVE-2025-13498 Download Manager [download-manager] < 3.3.33 Falta de control de autorización Media 4,3 < 3.3.33 3.3.33 2025-12-17 ✓ corregido en la última versión
CVE-2025-12177 Download Manager [download-manager] < 3.3.31 Uso de una clave criptográfica embebida en el código (hardcoded) Media 5,3 < 3.3.31 3.3.31 2025-11-07 ✓ corregido en la última versión
CVE-2025-63070 Download Manager [download-manager] < 3.3.33 Exposición de información sensible del sistema a una esfera de control no autorizada Media 4,3 < 3.3.33 3.3.33 2025-09-30 ✓ corregido en la última versión

CVE-2026-14343

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-13733

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although wp_kses_post is applied to post content on save, it only strips HTML tokens and does not neutralize C-style escape sequences embedded within shortcode attribute values, meaning contributors can craft a payload that survives the kses filter and is silently reconstructed into a raw script tag at render time.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-39676

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.3.52. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-39615

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-15364

The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-13498

The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-12177

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-63070

The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 100 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-60093 Download Manager [download-manager] < 3.3.25 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.3.25 3.3.25 2025-09-26 ✓ corregido en la última versión
CVE-2025-60092 Download Manager [download-manager] < 3.3.26 Exposición de información sensible del sistema a una esfera de control no autorizada Media 5,3 < 3.3.26 3.3.26 2025-09-26 ✓ corregido en la última versión
CVE-2024-13126 Download Manager [download-manager] < 3.3.07 Archivos o directorios accesibles a terceros Media 4,6 < 3.3.07 3.3.07 2025-01-17 ✓ corregido en la última versión
CVE-2024-56217 Download Manager [download-manager] < 3.3.04 Falta de control de autorización Media 4,3 < 3.3.04 3.3.04 2024-12-19 ✓ corregido en la última versión
CVE-2024-11740 Download Manager [download-manager] < 3.3.04 Control incorrecto de la generación de código (inyección de código) Alta 7,3 < 3.3.04 3.3.04 2024-12-18 ✓ corregido en la última versión
CVE-2024-11768 Download Manager [download-manager] < 3.3.04 Autorización indebida Media 5,3 < 3.3.04 3.3.04 2024-12-18 ✓ corregido en la última versión
CVE-2024-10706 Download Manager [download-manager] < 3.3.03 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.3.03 3.3.03 2024-11-29 ✓ corregido en la última versión
CVE-2024-8444 Download Manager [download-manager] < 3.3.00 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.3.00 3.3.00 2024-10-09 ✓ corregido en la última versión
CVE-2024-6208 Download Manager [download-manager] < 3.2.98 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.98 3.2.98 2024-07-30 ✓ corregido en la última versión
CVE-2024-2098 Download Manager [download-manager] < 3.2.90 Elusión de autenticación mediante un nombre alternativo Alta 7,5 < 3.2.90 3.2.90 2024-06-12 ✓ corregido en la última versión
CVE-2024-5266 Download Manager [download-manager] < 3.2.94 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.94 3.2.94 2024-06-11 ✓ corregido en la última versión
CVE-2024-1766 Download Manager [download-manager] < 3.2.87 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.87 3.2.87 2024-06-11 ✓ corregido en la última versión
CVE-2024-4001 Download Manager [download-manager] < 3.2.94 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.94 3.2.94 2024-06-04 ✓ corregido en la última versión
CVE-2024-4160 Download Manager [download-manager] < 3.2.91 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.91 3.2.91 2024-05-30 ✓ corregido en la última versión
CVE-2024-32131 Download Manager [download-manager] < 3.2.83 Exposición de información sensible a un actor no autorizado Alta 7,5 < 3.2.83 3.2.83 2024-04-12 ✓ corregido en la última versión
CVE-2024-29114 Download Manager [download-manager] < 3.2.85 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.2.85 3.2.85 2024-03-16 ✓ corregido en la última versión
CVE-2023-6785 Download Manager [download-manager] < 3.2.85 Control de acceso incorrecto Media 5,3 < 3.2.85 3.2.85 2024-02-28 ✓ corregido en la última versión
CVE-2023-6954 Download Manager [download-manager] < 3.2.86 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.86 3.2.86 2024-02-28 ✓ corregido en la última versión
CVE-2023-6421 Download Manager [download-manager] < 3.2.83 Credenciales insuficientemente protegidas Alta 7,5 < 3.2.83 3.2.83 2023-11-29 ✓ corregido en la última versión
CVE-2023-2305 Download Manager [download-manager] < 3.2.71 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.71 3.2.71 2023-05-12 ✓ corregido en la última versión
CVE-2023-1524 Download Manager [download-manager] < 3.2.71 Control de acceso incorrecto Media 6,5 < 3.2.71 3.2.71 2023-05-08 ✓ corregido en la última versión
CVE-2022-4476 Download Manager [download-manager] < 3.2.62 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.62 3.2.62 2022-12-20 ✓ corregido en la última versión
CVE-2022-45836 Download Manager [download-manager] < 3.2.60 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 3.2.60 3.2.60 2022-11-29 ✓ corregido en la última versión
CVE-2022-2926 Download Manager [download-manager] < 3.2.55 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 4,9 < 3.2.55 3.2.55 2022-09-05 ✓ corregido en la última versión
CVE-2022-2436 Download Manager [download-manager] < 3.2.71 Deserialización de datos no confiables Alta 8,8 < 3.2.71 3.2.71 2022-08-17 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.54 Desconocido < 3.2.54 3.2.54 2022-08-04 ✓ corregido en la última versión
CVE-2022-36288 Download Manager [download-manager] < 3.2.49 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 3.2.49 3.2.49 2022-08-02 ✓ corregido en la última versión
CVE-2022-34347 Download Manager [download-manager] < 3.2.49 Falsificación de petición en sitios cruzados (CSRF) Media 4,2 < 3.2.49 3.2.49 2022-08-02 ✓ corregido en la última versión
CVE-2022-2362 Download Manager [download-manager] < 3.2.50 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,5 < 3.2.50 3.2.50 2022-08-01 ✓ corregido en la última versión
CVE-2022-2431 Download Manager [download-manager] < 3.2.51 Control externo del nombre o la ruta de un archivo Alta 8,8 < 3.2.51 3.2.51 2022-07-27 ✓ corregido en la última versión
CVE-2022-34658 Download Manager [download-manager] < 3.2.49 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.49 3.2.49 2022-07-06 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.44 Desconocido < 3.2.44 3.2.44 2022-06-27 ✓ corregido en la última versión
CVE-2022-2168 Download Manager [download-manager] < 3.2.44 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.2.44 3.2.44 2022-06-27 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.44 Desconocido < 3.2.44 3.2.44 2022-06-23 ✓ corregido en la última versión
CVE-2022-2101 Download Manager [download-manager] < 3.2.47 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.47 3.2.47 2022-06-21 ✓ corregido en la última versión
CVE-2022-1985 Download Manager [download-manager] < 3.2.43 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.2.43 3.2.43 2022-06-02 ✓ corregido en la última versión
CVE-2022-0828 Download Manager [download-manager] < 3.2.39 Uso de un generador de números pseudoaleatorios criptográficamente débil (PRNG) Alta 7,5 < 3.2.39 3.2.39 2022-03-16 ✓ corregido en la última versión
CVE-2021-25087 Download Manager [download-manager] < 3.2.25 Falta de control de autorización Alta 7,5 < 3.2.25 3.2.25 2022-02-02 ✓ corregido en la última versión
CVE-2021-25069 Download Manager [download-manager] < 3.2.34 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 8,8 < 3.2.34 3.2.34 2022-01-12 ✓ corregido en la última versión
CVE-2021-24969 Download Manager [download-manager] < 3.2.22 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.22 3.2.22 2021-11-29 ✓ corregido en la última versión
CVE-2021-24773 Download Manager [download-manager] < 3.2.16 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.2.16 3.2.16 2021-09-29 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.13 Desconocido < 3.2.13 3.2.13 2021-08-09 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.13 Desconocido < 3.2.13 3.2.13 2021-08-09 ✓ corregido en la última versión
CVE-2021-34638 Download Manager [download-manager] < 3.1.25 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,5 < 3.1.25 3.1.25 2021-07-29 ✓ corregido en la última versión
CVE-2021-34639 Download Manager [download-manager] < 3.1.25 Carga de archivos sin restricción de tipo peligroso Alta 8,8 < 3.1.25 3.1.25 2021-07-29 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.22 Desconocido < 3.1.22 3.1.22 2021-04-30 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.23 Desconocido < 3.1.23 3.1.23 2021-04-30 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.19 Desconocido < 3.1.19 3.1.19 2021-04-30 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.17 Desconocido < 3.1.17 3.1.17 2021-04-16 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.97 Desconocido < 2.9.97 2.9.97 2019-06-16 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.97 Desconocido < 2.9.97 2.9.97 2019-06-16 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.94 Desconocido < 2.9.94 2.9.94 2019-04-23 ✓ corregido en la última versión
CVE-2019-15889 Download Manager [download-manager] < 2.9.94 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 2.9.94 2.9.94 2019-04-13 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.61 Desconocido < 2.9.61 2.9.61 2018-01-10 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.61 Desconocido < 2.9.61 2.9.61 2018-01-09 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.46 Desconocido < 2.9.46 2.9.46 2017-06-27 ✓ corregido en la última versión
CVE-2017-18032 Download Manager [download-manager] < 2.9.52 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 2.9.52 2.9.52 2017-06-16 ✓ corregido en la última versión
CVE-2017-2216 Download Manager [download-manager] < 2.9.50 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 2.9.50 2.9.50 2017-06-13 ✓ corregido en la última versión
CVE-2017-2217 Download Manager [download-manager] < 2.9.51 Redirección de URL a un sitio no confiable (Open Redirect) Media 6,1 < 2.9.51 2.9.51 2017-06-13 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.46 Desconocido < 2.9.46 2.9.46 2017-03-01 ✓ corregido en la última versión
Download Manager [download-manager] < 2.8.8 Desconocido < 2.8.8 2.8.8 2016-01-19 ✓ corregido en la última versión
Download Manager [download-manager] < 2.8.8 Desconocido < 2.8.8 2.8.8 2016-01-19 ✓ corregido en la última versión
Download Manager [download-manager] < 2.8.8 Desconocido < 2.8.8 2.8.8 2016-01-19 ✓ corregido en la última versión
Download Manager [download-manager] < 2.8.8 Desconocido < 2.8.8 2.8.8 2016-01-19 ✓ corregido en la última versión
Download Manager [download-manager] < 2.7.95 Desconocido < 2.7.95 2.7.95 2015-12-20 ✓ corregido en la última versión
Download Manager [download-manager] < 2.7.95 Desconocido < 2.7.95 2.7.95 2015-07-16 ✓ corregido en la última versión
Download Manager [download-manager] < 2.7.95 Desconocido < 2.7.95 2.7.95 2015-07-16 ✓ corregido en la última versión
Download Manager [download-manager] < 2.2.3 Desconocido < 2.2.3 2.2.3 2015-05-15 ✓ corregido en la última versión
Download Manager [download-manager] >= 2.7.0 - <= 2.7.4 Desconocido 2.7.0–2.7.4 2.7.4 2014-12-15 ✓ corregido en la última versión
Download Manager [download-manager] < 2.7.5 Desconocido < 2.7.5 2.7.5 2014-12-15 ✓ corregido en la última versión
CVE-2014-9260 Download Manager [download-manager] < 2.7.3 Alta 8,8 < 2.7.3 2.7.3 2014-11-24 ✓ corregido en la última versión
CVE-2014-8585 Download Manager [download-manager] < 2.7 Resolución incorrecta de enlaces antes de acceder a un archivo (Link Following) Desconocido < 2.7 2.7 2014-11-04 ✓ corregido en la última versión
Download Manager [download-manager] < 2.2.3 Desconocido < 2.2.3 2.2.3 2014-08-01 ✓ corregido en la última versión
CVE-2013-7319 Download Manager [download-manager] < 2.5.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 2.5.9 2.5.9 2013-12-08 ✓ corregido en la última versión
Download Manager [download-manager] < 2.5.9 Desconocido < 2.5.9 2.5.9 2013-12-07 ✓ corregido en la última versión
CVE-2024-8284 Download Manager [download-manager] < 3.2.99 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.2.99 3.2.99 0000-00-00 ✓ corregido en la última versión
CVE-2025-1785 Download Manager [download-manager] < 3.3.09 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 8,1 < 3.3.09 3.3.09 0000-00-00 ✓ corregido en la última versión
CVE-2025-3056 Download Manager [download-manager] < 3.3.13 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.3.13 3.3.13 0000-00-00 ✓ corregido en la última versión
CVE-2025-3404 Download Manager [download-manager] < 3.3.13 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 8,8 < 3.3.13 3.3.13 0000-00-00 ✓ corregido en la última versión
CVE-2025-4367 Download Manager [download-manager] < 3.3.19 Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) Media 5,4 < 3.3.19 3.3.19 0000-00-00 ✓ corregido en la última versión
CVE-2026-4057 Download Manager [download-manager] < 3.3.52 Desconocido < 3.3.52 3.3.52 0000-00-00 ✓ corregido en la última versión
CVE-2026-5357 Download Manager [download-manager] < 3.3.53 Desconocido < 3.3.53 3.3.53 0000-00-00 ✓ corregido en la última versión
CVE-2026-2571 Download Manager [download-manager] < 3.3.50 Desconocido < 3.3.50 3.3.50 0000-00-00 ✓ corregido en la última versión
CVE-2026-1666 Download Manager [download-manager] < 3.3.47 Desconocido < 3.3.47 3.3.47 0000-00-00 ✓ corregido en la última versión
Download Manager [download-manager] < 3.3.24 Media 6,1 < 3.3.24 3.3.24 0000-00-00 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.53 Desconocido < 3.2.53 3.2.53 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.44 Desconocido < 3.2.44 3.2.44 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.13 Desconocido < 3.2.13 3.2.13 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.19 Desconocido < 3.1.19 3.1.19 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.22 Desconocido < 3.1.22 3.1.22 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.23 Desconocido < 3.1.23 3.1.23 ✓ corregido en la última versión
Download Manager [download-manager] < 3.1.18 Desconocido < 3.1.18 3.1.18 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.97 Desconocido < 2.9.97 2.9.97 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.61 Desconocido < 2.9.61 2.9.61 ✓ corregido en la última versión
Download Manager [download-manager] < 2.9.46 Desconocido < 2.9.46 2.9.46 ✓ corregido en la última versión
Download Manager [download-manager] < 2.8.8 Desconocido < 2.8.8 2.8.8 ✓ corregido en la última versión
Download Manager [download-manager] < 2.7.95 Desconocido < 2.7.95 2.7.95 ✓ corregido en la última versión
Download Manager [download-manager] < 2.7.5 Desconocido < 2.7.5 2.7.5 ✓ corregido en la última versión
Download Manager [download-manager] < 2.2.3 Desconocido < 2.2.3 2.2.3 ✓ corregido en la última versión
Download Manager [download-manager] < 3.2.60 Desconocido < 3.2.60 3.2.60 ✓ corregido en la última versión

CVE-2025-60093

The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-60092

The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13126

The Download Manager plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 3.3.06. This is due to plugin not providing any access restrictions to the direct in which download files are uploaded. This makes it possible for unauthenticated attackers to access downloads that should be password protected by downloading them straight from the directory.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-56217

The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.03. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-11740

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-11768

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-10706

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.02 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-8444

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_login_form' shortcode in all versions up to, and including, 3.2.99 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-6208

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2098

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-5266

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-1766

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4001

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4160

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-32131

No patched version is available. No reply from the vendor since Nov 15, 2023. We have notified the WP plugins review team. Liu Shaohong discovered and reported this Bypass Vulnerability vulnerability in WordPress Download Manager Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has not been known to be fixed yet. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-29114

Update the WordPress Download Manager plugin to the latest available version (at least 3.2.85). LVT-tholv2k discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.85. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6785

Update the WordPress Download Manager plugin to the latest available version (at least 3.2.85). wesley (wcraft) discovered and reported this Broken Access Control vulnerability in WordPress Download Manager Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.2.85. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6954

Update the WordPress Download Manager plugin to the latest available version (at least 3.2.86). Richard Telleng (stueotue) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.86. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6421

The Download Manager plugin for WordPress is vulnerable to information Exposure in all versions up to, and including, 3.2.82. This is due to the plugin leaking the password to a protected file when it receives an invalid password. This makes it possible for unauthenticated attackers to gain access to protected files.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-2305

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-1524

The Download Manager plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.2.7.0, due to insufficient validation of passwords on password protected files. This makes it possible for authenticated attackers, with access to the downloads area to create a password protected post which returns a master key, and then subsequently use that master key and original password to access any other password protected post.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-4476

Update the WordPress Download Manager plugin to the latest available version (at least 3.2.62). Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.62.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-45836

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘packages-shortcode-toolbar.php’, 'Shortcodes.php', and 'category-shortcode-toolbar.php' (in both 'src/Package/views/' and 'src/Category/views/') files in versions up to, and including, 3.2.59 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute if they can successfully trick a victim into clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2926

The Download Manager plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.2.54 via the File Browser Root field. This makes it possible for administrator-level attackers to list and read arbitrary files and folders outside of the blog directory.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2436

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Download Manager [download-manager] < 3.2.54

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQUEST_URI'] in an echo statement without appropriate escaping on the URL in versions up to, and including, 3.2.53. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-36288

The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete stats and clear the plugin's cache via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-34347

The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.48. This is due to missing or incorrect nonce validation on the updateTemplateStatus function. This makes it possible for unauthenticated attackers to trigger setting changes forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2362

The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 due to the way the visitor's IP address is determined. This allows an unauthenticated attacker to spoof their IP address to obtain access to files that are protected by this functionality.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2431

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the /wp-config.php file which will reset the installation and make it possible for an attacker to achieve remote code execution on the server.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-34658

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ and 'label' parameters in versions up to, and including, 3.2.48 due to insufficient input sanitization and output escaping when setting lock options for downloadables. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 3.2.44

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Download Manager plugin (versions <= 3.2.43). Update the WordPress Download Manager plugin to the latest available version (at least 3.2.44).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-2168

Reflected Cross-Site Scripting (XSS) vulnerability discovered by ZhongFu Su aka JrXnm (WuHan University) in WordPress Download Manager plugin (versions <= 3.2.43). Update the WordPress Download Manager plugin to the latest available version (at least 3.2.44).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 3.2.44

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in versions up to, and including, 3.2.43 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2101

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-1985

The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-0828

The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-25087

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-25069

The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24969

The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24773

The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Download Manager [download-manager] < 3.2.13

Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Download Manager plugin (versions <= 3.2.12).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 3.2.13

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.12. This is due to missing or incorrect nonce validation on the preview() function. This makes it possible for unauthenticated attackers to save the plugins email settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-34638

Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-34639

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. The destination folder is also protected by an .htaccess file affecting the same configurations so this is likely difficult to exploit in the real world.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.1.22

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 3.1.23

The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.1.23. This is due to the same nonce being using for multiple AJAX actions. This makes it possible for authenticated attackers with low level privileges to reveal the nonce in pages available to them and use it to perform unauthorized actions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 3.1.19

The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level privileges and above to upload arbitrary files on the affected sites server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 3.1.17

The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable sites downloads.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.9.97

Multiple vulnerabilities found in WordPress Download Manager plugin (versions <= 2.9.96).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 2.9.97

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.96 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.9.94

Authenticated Cross-Site Scripting (XSS) vulnerability found by MgThuraMoeMyint on WordPress Download Manager plugin (versions <= 2.9.93).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-15889

In the pro features of the WordPress download manager plugin, there is a Category Short-code feature witch can use to sort categories with order by a function which will be used as ?orderby=title,publish_date . By adding parameter "> and add any XSS payload , the xss payload will execute. To reproduce, 1. Go to the link where we can find ?orderby 2. Add parameters >" and give simple payload like <script>alert(1)</script> 3. The payload will execute. Another reflected cross-site scripting via advance search .

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.9.61

Cross-Site Request Forgery (CSRF) vulnerability found by Panagiotis Vagenas in WordPress Download Manager plugin (versions <=2.9.60).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 2.9.61

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the wpdm_install_addon function. This makes it possible for unauthenticated attackers to install malicious plugins and/or packages via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.9.46

Authenticated Arbitrary File Upload Vulnerability exsists in WordPress WordPress Download Manager plugin <= 2.8.97 . It doesn't check what type of files you can upload so an attacker can upload .PHP files. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2017-18032

The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2017-2216

The WordPress Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in versions up to, and including, 2.9.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2017-2217

The WordPress plugin "WordPress Download Manager" provided by W3 Eden, Inc. contains an open redirect vulnerability (CWE-601). Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

Download Manager [download-manager] < 2.9.46

The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.45. This is due to missing or incorrect nonce validation on the request of saving settings. This makes it possible for unauthenticated attackers to modify administrative settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.8.8

This plugin is prone to privilege escalation, unauthenticated directory listings and unauthenticated post updating vulnerabilities. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 2.8.8

The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. This is due to the 'wpdm_dir_tree()' function being called during the 'init' action. This makes it possible for unauthenticated attackers to read all of the files listed in that directory.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.8.8

The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.8.8

The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the savePackage() function in versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to associate arbitrary files with posts and subsequently download those files causing sensitive information disclosure.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.7.95

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 2.7.95

Download Manager Free and Pro is prone to an authenticated stored XSS that allows an attacker to create new download package and upload files, called <svg onload=alert(0)>.jpg. This vulnerability works, when user try to edit this download package. Upgrade to the latest version.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 2.7.95

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded file in versions up to, and including, 2.7.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 2.2.3

This plugin is prone to admin.php cid parameter cross site scripting vulnerability. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] >= 2.7.0 - <= 2.7.4

Download Manager plugin is prone to a remote code execution vulnerability via "/download-manager/wpdm-core.php". It allows attackers to execute arbitrary PHP code. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 2.7.5

The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4 via the wpdm_ajax_call_exec() function. This allows unauthorized attackers to execute code on the server.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2014-9260

Download Manager plugin is prone tu vulnerability that allows an attacker to take control of every group (change name, description, avatar and settings). In this case, every registered user can update every WordPress options using basic_settings() function. Update to version 2.7.3.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2014-8585

Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Download Manager [download-manager] < 2.2.3

The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2013-7319

Download Manager Free & Pro plugin is prone to a persistent XSS vulnerability. The title input field is not sanitized and therefor vulnerable to persistent cross site scripting. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Download Manager [download-manager] < 2.5.9

The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-8284

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.98 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-1785

The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-3056

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-3404

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-4367

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-4057

The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without verifying post ownership via `current_user_can('edit_post', $id)`, and the destructive operations executing before the admin-level check in `mediaAccessControl()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to strip all protection metadata (password, access restrictions, private flag) from any media file they do not own, making admin-protected files publicly accessible via their direct URL.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-5357

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is extracted without sanitization in the members() function and stored via update_post_meta(), then echoed directly into an HTML id attribute in the members.php template without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2571

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-1666

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Download Manager [download-manager] < 3.3.24

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Download Manager [download-manager] < 3.2.53

The plugin does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute of the modal login page (only available when users are not logged in), which could lead to Reflected Cross-Site Scripting in old web browsers.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.2.44

The plugin does not escape a generated URL before outputting it back in an attribute of the login page made by the plugin, leading to Reflected Cross-Site Scripting, which is only exploitable against unauthenticated users

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.2.13

The plugin did not have CSRF check in place before saving its Email Template setting, allowing attackers to make a logged in admin change them via a CSRF attack

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.1.19

The wpdm_admin_upload_file AJAX action used a blacklist approach to forbid potential dangerous files, such as PHP, from being uploaded. However, other dangerous extensions, like .php4 were not forbidden.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.1.22

The wpdm_settings AJAX action, used the section POST parameter to call the associated settings handler methods dynamically. However, the pluginUpdate() (section=plugin-update) and Privacy() (section=privacy) were missing CSRF checks. Furthermore, the Privacy() function did not ensure that the options to be updated were actually related to privacy, allowing any option key containing _wpdm_ to be updated.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.1.23

The majority of the AJAX actions related to the Asset Manager use the same nonce action (ie the NONCE_KEY constant), and are lacking any authorisation checks. Given that the nonce is available in other pages, accessible by low priviledge users (such as author, or even subscribers depending on the plugin's feature used), this could lead to unauthorised use of the Asset Manager. Exploitation of the mkDir, newFile, scanDir, createZip, unZip, deleteItem, openFile, fileSettings, saveFile, moveItem, copyItem would be quite difficult to achieve, as their file/path parameters are encrypted using SECURE_AUTH_KEY or NONCE_SALT, nonetheless, they should be properly secured. However, the addComment, addShareLink, getLinkDet, updateLink, deleteLink and renameItem can be exploited.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.1.18

The duplicate() method, hooked to the admin_init action did not have any CSRF and authorisation checks, allowing unauthorised users (such as unauthenticated ones) to duplicate arbitrary downloads

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.9.97

The WordPress Download Manager WordPress plugin was affected by a Various Sanitisation Issues security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.9.61

The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.9.46

The WordPress Download Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.8.8

Numerous vulnerabilities with WordPress Download Manager free and pro versions. Privilege escalation, directory listing and unauthorised file download.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.7.95

The stored XSS vulnerability allows any authenticated user to inject malicious code via the name of the uploaded file: Example: <svg onload=alert(0)>.jpg The vulnerability exists because the file name is not properly sanitized and this can lead to malicious code injection that will be executed on the target’s browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.7.5

The WordPress Download Manager WordPress plugin was affected by a Code Execution / Remote File Inclusion security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 2.2.3

The WordPress Download Manager WordPress plugin was affected by an admin.php cid Parameter XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Download Manager [download-manager] < 3.2.60

Update the WordPress Download Manager plugin to the latest available version (at least 3.2.60). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.60.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Cómo solucionarlo

Mantén Download Manager actualizado — 3.3.66 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.