← WordPress Vulnerabilities
WordPress security by component

CM Download Manager

CM Download Manager is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Apr 01, 2025; the highest CVE/CNA score is 10.

Plugin slug: cm-download-manager

CVE-2025-30910: CM Download Manager: Filesystem traversal

CM Download Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedApr 01, 2025
Safe version guidanceSee mitigation notes
Safe version
Apr 01, 2025 CVE-2025-30910
CM Download Manager: Filesystem traversal
CM Download Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.6
NVDPending
Mar 25, 2024 CVE-2024-1962
CM Download Manager: Cross-site request forgery
CM Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending
Mar 25, 2024 CVE-2024-1232
CM Download Manager: Cross-site request forgery
CM Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.8
NVDPending
Mar 25, 2024 CVE-2024-1231
CM Download Manager: Cross-site request forgery
CM Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.8
NVDPending
Sep 26, 2022 CVE-2022-3076
CM Download Manager: A security weakness
CM Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Jul 07, 2021 CVE-2020-24146
Cm Download Manager: Filesystem traversal
Cm Download Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVD8.1
Jul 07, 2021 CVE-2020-24145
Cm Download Manager: Cross-site scripting
Cm Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 21, 2020 CVE-2020-27344
Cm Download Manager: Cross-site scripting
Cm Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Dec 05, 2014 CVE-2014-8877
Cm Download Manager: A security weakness
Cm Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE10.0
NVD10.0
Dec 05, 2014 CVE-2014-9129
Cm Download Manager: Cross-site scripting
Cm Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.8
NVD6.8