PLUGIN SECURITY
Is Download Manager safe?
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
What this plugin does
- Slug:
download-manager - Author: Shahjada
- 100000+ active installs
- 82/100 rating (1007 reviews on wordpress.org)
- 11391464 all-time downloads
- On WordPress.org since 2010-02-10
digital storedocument managementdownload managerecommercefile manager
Maintenance status
- Latest known version: 3.3.67
- Last updated: 2026-08-21 5:51am GMT
- Tested up to WordPress: 7.1
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
69 known CVEs on file for Download Manager.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-14292 | Download Manager [download-manager] < 3.3.66 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 3.3.66 | 3.3.66 | 2026-08-01 | ✓ fixed in latest |
| CVE-2026-16685 | Download Manager [download-manager] < 3.3.67 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.3.67 | 3.3.67 | 2026-07-08 | ✓ fixed in latest |
| CVE-2026-13733 | Download Manager [download-manager] < 3.3.61 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.3.61 | 3.3.61 | 2026-06-30 | ✓ fixed in latest |
| CVE-2026-14343 | Download Manager [download-manager] < 3.3.62 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.3.62 | 3.3.62 | 2026-06-30 | ✓ fixed in latest |
| CVE-2026-39676 | Download Manager [download-manager] < 3.3.53 | — | Medium 5.3 | < 3.3.53 | 3.3.53 | 2026-02-19 | ✓ fixed in latest |
| CVE-2026-39615 | Download Manager [download-manager] < 3.3.54 | — | Medium 5.9 | < 3.3.54 | 3.3.54 | 2026-02-10 | ✓ fixed in latest |
| CVE-2025-15364 | Download Manager [download-manager] < 3.3.41 | Missing Support for Integrity Check | High 7.3 | < 3.3.41 | 3.3.41 | 2026-01-05 | ✓ fixed in latest |
| CVE-2025-13498 | Download Manager [download-manager] < 3.3.33 | Missing Authorization | Medium 4.3 | < 3.3.33 | 3.3.33 | 2025-12-17 | ✓ fixed in latest |
+ 128 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-12177 | Download Manager [download-manager] < 3.3.31 | Use of Hard-coded Cryptographic Key | Medium 5.3 | < 3.3.31 | 3.3.31 | 2025-11-07 | ✓ fixed in latest |
| CVE-2025-63070 | Download Manager [download-manager] < 3.3.33 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Medium 4.3 | < 3.3.33 | 3.3.33 | 2025-09-30 | ✓ fixed in latest |
| CVE-2025-60093 | Download Manager [download-manager] < 3.3.25 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.3.25 | 3.3.25 | 2025-09-26 | ✓ fixed in latest |
| CVE-2025-60092 | Download Manager [download-manager] < 3.3.26 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Medium 5.3 | < 3.3.26 | 3.3.26 | 2025-09-26 | ✓ fixed in latest |
| CVE-2024-13126 | Download Manager [download-manager] < 3.3.07 | Files or Directories Accessible to External Parties | Medium 4.6 | < 3.3.07 | 3.3.07 | 2025-01-17 | ✓ fixed in latest |
| CVE-2024-56217 | Download Manager [download-manager] < 3.3.04 | Missing Authorization | Medium 4.3 | < 3.3.04 | 3.3.04 | 2024-12-19 | ✓ fixed in latest |
| CVE-2024-11740 | Download Manager [download-manager] < 3.3.04 | Improper Control of Generation of Code ('Code Injection') | High 7.3 | < 3.3.04 | 3.3.04 | 2024-12-18 | ✓ fixed in latest |
| CVE-2024-11768 | Download Manager [download-manager] < 3.3.04 | Improper Authorization | Medium 5.3 | < 3.3.04 | 3.3.04 | 2024-12-18 | ✓ fixed in latest |
| CVE-2024-10706 | Download Manager [download-manager] < 3.3.03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.3.03 | 3.3.03 | 2024-11-29 | ✓ fixed in latest |
| CVE-2024-8444 | Download Manager [download-manager] < 3.3.00 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.3.00 | 3.3.00 | 2024-10-09 | ✓ fixed in latest |
| CVE-2024-6208 | Download Manager [download-manager] < 3.2.98 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.98 | 3.2.98 | 2024-07-30 | ✓ fixed in latest |
| CVE-2024-2098 | Download Manager [download-manager] < 3.2.90 | Authentication Bypass by Alternate Name | High 7.5 | < 3.2.90 | 3.2.90 | 2024-06-12 | ✓ fixed in latest |
| CVE-2024-5266 | Download Manager [download-manager] < 3.2.94 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.94 | 3.2.94 | 2024-06-11 | ✓ fixed in latest |
| CVE-2024-1766 | Download Manager [download-manager] < 3.2.87 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.87 | 3.2.87 | 2024-06-11 | ✓ fixed in latest |
| CVE-2024-4001 | Download Manager [download-manager] < 3.2.94 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.94 | 3.2.94 | 2024-06-04 | ✓ fixed in latest |
| CVE-2024-4160 | Download Manager [download-manager] < 3.2.91 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.91 | 3.2.91 | 2024-05-30 | ✓ fixed in latest |
| CVE-2024-32131 | Download Manager [download-manager] < 3.2.83 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 3.2.83 | 3.2.83 | 2024-04-12 | ✓ fixed in latest |
| CVE-2024-29114 | Download Manager [download-manager] < 3.2.85 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.2.85 | 3.2.85 | 2024-03-16 | ✓ fixed in latest |
| CVE-2023-6785 | Download Manager [download-manager] < 3.2.85 | Improper Access Control | Medium 5.3 | < 3.2.85 | 3.2.85 | 2024-02-28 | ✓ fixed in latest |
| CVE-2023-6954 | Download Manager [download-manager] < 3.2.86 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.86 | 3.2.86 | 2024-02-28 | ✓ fixed in latest |
| CVE-2023-6421 | Download Manager [download-manager] < 3.2.83 | Insufficiently Protected Credentials | High 7.5 | < 3.2.83 | 3.2.83 | 2023-11-29 | ✓ fixed in latest |
| CVE-2023-2305 | Download Manager [download-manager] < 3.2.71 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.71 | 3.2.71 | 2023-05-12 | ✓ fixed in latest |
| CVE-2023-1524 | Download Manager [download-manager] < 3.2.71 | Improper Access Control | Medium 6.5 | < 3.2.71 | 3.2.71 | 2023-05-08 | ✓ fixed in latest |
| CVE-2022-4476 | Download Manager [download-manager] < 3.2.62 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.62 | 3.2.62 | 2022-12-20 | ✓ fixed in latest |
| CVE-2022-45836 | Download Manager [download-manager] < 3.2.60 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.2.60 | 3.2.60 | 2022-11-29 | ✓ fixed in latest |
| CVE-2022-2926 | Download Manager [download-manager] < 3.2.55 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 4.9 | < 3.2.55 | 3.2.55 | 2022-09-05 | ✓ fixed in latest |
| CVE-2022-2436 | Download Manager [download-manager] < 3.2.71 | Deserialization of Untrusted Data | High 8.8 | < 3.2.71 | 3.2.71 | 2022-08-17 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.54 | — | Unknown | < 3.2.54 | 3.2.54 | 2022-08-04 | ✓ fixed in latest |
| CVE-2022-36288 | Download Manager [download-manager] < 3.2.49 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 3.2.49 | 3.2.49 | 2022-08-02 | ✓ fixed in latest |
| CVE-2022-34347 | Download Manager [download-manager] < 3.2.49 | Cross-Site Request Forgery (CSRF) | Medium 4.2 | < 3.2.49 | 3.2.49 | 2022-08-02 | ✓ fixed in latest |
| CVE-2022-2362 | Download Manager [download-manager] < 3.2.50 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.5 | < 3.2.50 | 3.2.50 | 2022-08-01 | ✓ fixed in latest |
| CVE-2022-2431 | Download Manager [download-manager] < 3.2.51 | External Control of File Name or Path | High 8.8 | < 3.2.51 | 3.2.51 | 2022-07-27 | ✓ fixed in latest |
| CVE-2022-34658 | Download Manager [download-manager] < 3.2.49 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.49 | 3.2.49 | 2022-07-06 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.44 | — | Unknown | < 3.2.44 | 3.2.44 | 2022-06-27 | ✓ fixed in latest |
| CVE-2022-2168 | Download Manager [download-manager] < 3.2.44 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.2.44 | 3.2.44 | 2022-06-27 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.44 | — | Unknown | < 3.2.44 | 3.2.44 | 2022-06-23 | ✓ fixed in latest |
| CVE-2022-2101 | Download Manager [download-manager] < 3.2.47 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.48 | 3.2.48 | 2022-06-21 | ✓ fixed in latest |
| CVE-2022-1985 | Download Manager [download-manager] < 3.2.43 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.2.43 | 3.2.43 | 2022-06-02 | ✓ fixed in latest |
| CVE-2022-0828 | Download Manager [download-manager] < 3.2.39 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | High 7.5 | < 3.2.39 | 3.2.39 | 2022-03-16 | ✓ fixed in latest |
| CVE-2021-25087 | Download Manager [download-manager] < 3.2.25 | Missing Authorization | High 7.5 | < 3.2.35 | 3.2.35 | 2022-02-02 | ✓ fixed in latest |
| CVE-2021-25069 | Download Manager [download-manager] < 3.2.34 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 3.2.34 | 3.2.34 | 2022-01-12 | ✓ fixed in latest |
| CVE-2021-24969 | Download Manager [download-manager] < 3.2.22 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.22 | 3.2.22 | 2021-11-29 | ✓ fixed in latest |
| CVE-2021-24773 | Download Manager [download-manager] < 3.2.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.2.16 | 3.2.16 | 2021-09-29 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.13 | — | Unknown | < 3.2.13 | 3.2.13 | 2021-08-09 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.13 | — | Unknown | < 3.2.13 | 3.2.13 | 2021-08-09 | ✓ fixed in latest |
| CVE-2021-34638 | Download Manager [download-manager] < 3.1.25 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 3.1.25 | 3.1.25 | 2021-07-29 | ✓ fixed in latest |
| CVE-2021-34639 | Download Manager [download-manager] < 3.1.25 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 3.1.25 | 3.1.25 | 2021-07-29 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.22 | — | Unknown | < 3.1.22 | 3.1.22 | 2021-04-30 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.23 | — | Unknown | < 3.1.23 | 3.1.23 | 2021-04-30 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.19 | — | Unknown | < 3.1.19 | 3.1.19 | 2021-04-30 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.17 | — | Unknown | < 3.1.17 | 3.1.17 | 2021-04-16 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.97 | — | Unknown | < 2.9.97 | 2.9.97 | 2019-06-16 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.97 | — | Unknown | < 2.9.97 | 2.9.97 | 2019-06-16 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.94 | — | Unknown | < 2.9.94 | 2.9.94 | 2019-04-23 | ✓ fixed in latest |
| CVE-2019-15889 | Download Manager [download-manager] < 2.9.94 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.9.94 | 2.9.94 | 2019-04-13 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.61 | — | Unknown | < 2.9.61 | 2.9.61 | 2018-01-10 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.61 | — | Unknown | < 2.9.61 | 2.9.61 | 2018-01-09 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.46 | — | Unknown | < 2.9.46 | 2.9.46 | 2017-06-27 | ✓ fixed in latest |
| CVE-2017-18032 | Download Manager [download-manager] < 2.9.52 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.9.52 | 2.9.52 | 2017-06-16 | ✓ fixed in latest |
| CVE-2017-2216 | Download Manager [download-manager] < 2.9.50 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.9.50 | 2.9.50 | 2017-06-13 | ✓ fixed in latest |
| CVE-2017-2217 | Download Manager [download-manager] < 2.9.51 | URL Redirection to Untrusted Site ('Open Redirect') | Medium 6.1 | < 2.9.51 | 2.9.51 | 2017-06-13 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.46 | — | Unknown | < 2.9.46 | 2.9.46 | 2017-03-01 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.8.8 | — | Unknown | < 2.8.8 | 2.8.8 | 2016-01-19 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.8.8 | — | Unknown | < 2.8.8 | 2.8.8 | 2016-01-19 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.8.8 | — | Unknown | < 2.8.8 | 2.8.8 | 2016-01-19 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.8.8 | — | Unknown | < 2.8.8 | 2.8.8 | 2016-01-19 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.7.95 | — | Unknown | < 2.7.95 | 2.7.95 | 2015-12-20 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.7.95 | — | Unknown | < 2.7.95 | 2.7.95 | 2015-07-16 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.7.95 | — | Unknown | < 2.7.95 | 2.7.95 | 2015-07-16 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.2.3 | — | Unknown | < 2.2.3 | 2.2.3 | 2015-05-15 | ✓ fixed in latest |
| — | Download Manager [download-manager] >= 2.7.0 - <= 2.7.4 | — | Unknown | 2.7.0–2.7.4 | 2.7.4 | 2014-12-15 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.7.5 | — | Unknown | < 2.7.5 | 2.7.5 | 2014-12-15 | ✓ fixed in latest |
| CVE-2014-9260 | Download Manager [download-manager] < 2.7.3 | — | High 8.8 | < 2.7.3 | 2.7.3 | 2014-11-24 | ✓ fixed in latest |
| CVE-2014-8585 | Download Manager [download-manager] < 2.7 | Improper Link Resolution Before File Access ('Link Following') | Unknown | < 2.7 | 2.7 | 2014-11-04 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.2.3 | — | Unknown | < 2.2.3 | 2.2.3 | 2014-08-01 | ✓ fixed in latest |
| CVE-2013-7319 | Download Manager [download-manager] < 2.5.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 2.5.9 | 2.5.9 | 2013-12-08 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.5.9 | — | Unknown | < 2.5.9 | 2.5.9 | 2013-12-07 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.99 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.2.99 | 3.2.99 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.09 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.1 | < 3.3.09 | 3.3.09 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.3.13 | 3.3.13 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.13 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 3.3.13 | 3.3.13 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.19 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 5.4 | < 3.3.19 | 3.3.19 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.52 | — | Unknown | < 3.3.52 | 3.3.52 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.53 | — | Unknown | < 3.3.53 | 3.3.53 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.50 | — | Unknown | < 3.3.50 | 3.3.50 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.47 | — | Unknown | < 3.3.47 | 3.3.47 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.3.24 | — | Medium 6.1 | < 3.3.24 | 3.3.24 | 0000-00-00 | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.53 | — | Unknown | < 3.2.53 | 3.2.53 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.44 | — | Unknown | < 3.2.44 | 3.2.44 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.13 | — | Unknown | < 3.2.13 | 3.2.13 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.19 | — | Unknown | < 3.1.19 | 3.1.19 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.22 | — | Unknown | < 3.1.22 | 3.1.22 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.23 | — | Unknown | < 3.1.23 | 3.1.23 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.1.18 | — | Unknown | < 3.1.18 | 3.1.18 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.97 | — | Unknown | < 2.9.97 | 2.9.97 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.61 | — | Unknown | < 2.9.61 | 2.9.61 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.9.46 | — | Unknown | < 2.9.46 | 2.9.46 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.8.8 | — | Unknown | < 2.8.8 | 2.8.8 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.7.95 | — | Unknown | < 2.7.95 | 2.7.95 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.7.5 | — | Unknown | < 2.7.5 | 2.7.5 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 2.2.3 | — | Unknown | < 2.2.3 | 2.2.3 | — | ✓ fixed in latest |
| — | Download Manager [download-manager] < 3.2.60 | — | Unknown | < 3.2.60 | 3.2.60 | — | ✓ fixed in latest |
| — | Download Manager <= 2.2.2 - admin.php cid Parameter XSS | — | Unknown | < 2.2.3 | 2.2.3 | — | ✓ fixed in latest |
| — | Download Manager <= 2.7.4 - Code Execution / Remote File Inclusion | — | Unknown | < 2.7.5 | 2.7.5 | — | ✓ fixed in latest |
| — | Download Manager <= 2.7.94 - Authenticated Stored XSS | — | Unknown | < 2.7.95 | 2.7.95 | — | ✓ fixed in latest |
| — | Download Manager <= 2.8.7 - Multiple Vulnerabilities | — | Unknown | < 2.8.8 | 2.8.8 | — | ✓ fixed in latest |
| — | Download Manager <= 2.9.45 - Cross-Site Request Forgery (CSRF) | — | Unknown | < 2.9.46 | 2.9.46 | — | ✓ fixed in latest |
| — | Download Manager <= 2.9.60 - Cross-Site Request Forgery (CSRF) | — | Unknown | < 2.9.61 | 2.9.61 | — | ✓ fixed in latest |
| — | Download Manager <= 2.9.96 - Various Sanitisation Issues | — | Unknown | < 2.9.97 | 2.9.97 | — | ✓ fixed in latest |
| — | WordPress Download Manager < 3.1.18 - Unauthorised Download Duplication | — | Unknown | < 3.1.18 | 3.1.18 | — | ✓ fixed in latest |
| — | Download Manager < 3.1.23 - Unauthorised Asset Manager Usage | — | Unknown | < 3.1.23 | 3.1.23 | — | ✓ fixed in latest |
| — | Download Manager < 3.1.22 - Plugin Settings Change via CSRF | — | Unknown | < 3.1.22 | 3.1.22 | — | ✓ fixed in latest |
| — | Download Manager < 3.1.19 - Authenticated (author+) PHP4 File Upload to RCE | — | Unknown | < 3.1.19 | 3.1.19 | — | ✓ fixed in latest |
| — | WordPress Download Manager < 3.2.13 - Email Template Setting Update via CSRF | — | Unknown | < 3.2.13 | 3.2.13 | — | ✓ fixed in latest |
| — | Download Manager < 3.2.44 - Unauthenticated Reflected Cross-Site Scripting | — | Unknown | < 3.2.44 | 3.2.44 | — | ✓ fixed in latest |
| — | Download Manager < 3.2.53 - Unauthenticated Reflected Cross-Site Scripting | — | Unknown | < 3.2.53 | 3.2.53 | — | ✓ fixed in latest |
| CVE-2023-1809 | Download Manager Pro < 6.3.0 - Unauthenticated Sensitive Information Disclosure | — | Unknown | < 6.3.0 | 6.3.0 | — | ⚠ update needed |
| CVE-2024-8284 | Download Manager <= 3.2.98 - Admin+ Stored XSS | — | Unknown | < 3.2.99 | 3.2.99 | — | ✓ fixed in latest |
| CVE-2025-1785 | Download Manager < 3.3.09 - Authenticated (Author+) Path Traversal to Limited File Overwrite | — | Unknown | < 3.3.09 | 3.3.09 | — | ✓ fixed in latest |
| CVE-2025-3056 | Download Manager < 3.3.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | — | Unknown | < 3.3.13 | 3.3.13 | — | ✓ fixed in latest |
| CVE-2025-3404 | Download Manager < 3.3.13 - Author+ Arbitrary File Deletion | — | Unknown | < 3.3.13 | 3.3.13 | — | ✓ fixed in latest |
| CVE-2025-4367 | Download Manager < 3.3.19 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode | — | Unknown | < 3.3.19 | 3.3.19 | — | ✓ fixed in latest |
| CVE-2025-10146 | Download Manager < 3.3.24 - Reflected Cross-Site Scripting via `user_ids` Parameter | — | Unknown | < 3.3.24 | 3.3.24 | — | ✓ fixed in latest |
| CVE-2026-1666 | Download Manager < 3.3.47 - Reflected Cross-Site Scripting via 'redirect_to' Parameter | — | Unknown | < 3.3.47 | 3.3.47 | — | ✓ fixed in latest |
| CVE-2026-2571 | Download Manager < 3.3.50 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter | — | Unknown | < 3.3.50 | 3.3.50 | — | ✓ fixed in latest |
| CVE-2026-5357 | Download Manager < 3.3.53 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | — | Unknown | < 3.3.53 | 3.3.53 | — | ✓ fixed in latest |
| CVE-2026-4057 | Download Manager < 3.3.52 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal | — | Unknown | < 3.3.52 | 3.3.52 | — | ✓ fixed in latest |
| CVE-2026-14235 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key | — | Unknown | < 3.3.62 | 3.3.62 | — | ✓ fixed in latest |
How to fix it
Keep Download Manager updated — 3.3.67 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution — 100000+ active installs — 96/100 (438) — max PHP 8.4
- Download Monitor — 80000+ active installs — 90/100 (524) — max PHP <8.0
- Easy Digital Downloads – eCommerce Payments and Subscriptions made easy — 40000+ active installs — 94/100 (590)
- Download Manager Addons for Elementor — 6000+ active installs — 44/100 (5)
- Document Library Lite — 4000+ active installs — 80/100 (11) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.