Download Manager
Download Manager organizes, manages, and delivers downloadable files through WordPress with controlled access and download tracking.
Download Manager (download-manager) is a WordPress plugin with 70 published CVE records in this archive. The latest tracked vulnerability was published Sep 18, 2026; the highest published CVSS base score is 8.8.
download-managerCVE-2026-92714: Download Manager: Package duplication bypasses protected-download restrictions
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata — including protected file references, role-based access restrictions, and password lock settings — into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files. The export states Author-level access, while the matching changelog describes Contributor-level exposure; both identify the same object-authorization failure. Affected versions reported by the CNA: <= 3.3.68. Official changelog review confirms 3.3.69 as a fixed release for this issue.
| Safe version |
|
||
|---|---|---|---|
| Sep 18, 2026 |
CVE-2026-92714
Download Manager: Package duplication bypasses protected-download restrictions
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata — including protected file references, role-based access restrictions, and password lock settings — into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files. The export states Author-level access, while the matching changelog describes Contributor-level exposure; both identify the same object-authorization failure. Affected versions reported by the CNA: <= 3.3.68. Official changelog review confirms 3.3.69 as a fixed release for this issue.
|
3.3.69 |
CVE6.5
NVDPending
|
| Aug 01, 2026 |
CVE-2026-16685
Download Manager icon attributes let Contributors store JavaScript
Download Manager through 3.3.66 emits the icon attribute of its category shortcode without adequate escaping. A Contributor can store a payload inside the shortcode attribute that bypasses save-time wp_kses_post() and executes when the shortcode renders for a visitor or Administrator.
|
> 3.3.66 |
CVE6.4
NVDPending
|
| Aug 01, 2026 |
CVE-2026-14292
Download Manager package titles let Authors store JavaScript
Download Manager before 3.3.66 does not properly escape a package title in its front-end templates. An Author-or-higher user can save a title containing a script payload, and that JavaScript executes in the browser of any logged-in or anonymous visitor who views a page displaying the package.
|
3.3.66 |
CVE5.4
NVDPending
|
| Jul 27, 2026 |
CVE-2026-14235
Download Manager tokens remain reusable outside the issuing session
Download Manager before 3.3.62 issues temporary download tokens that are not bound to the session that requested them and are not promptly expired. Anyone who obtains a leaked token can reuse it as a long-lived bearer credential to repeatedly download a role-protected or password-protected package without the original user's session.
|
3.3.62 |
CVE7.5
NVDPending
|
| Jul 09, 2026 |
CVE-2026-14343
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.61.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 01, 2026 |
CVE-2026-13733
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.60.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 10, 2026 |
CVE-2026-4057
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.51.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 09, 2026 |
CVE-2026-5357
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.52.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39676
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.52.
|
3.3.53 |
CVE5.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39615
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.53.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 19, 2026 |
CVE-2026-2571
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1666
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jan 06, 2026 |
CVE-2025-15364
Download Manager: Privilege escalation or authentication bypass
Download Manager is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE7.3
NVDPending
|
| Dec 18, 2025 |
CVE-2025-13498
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 09, 2025 |
CVE-2025-63070
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 08, 2025 |
CVE-2025-12177
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 26, 2025 |
CVE-2025-60093
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 26, 2025 |
CVE-2025-60092
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 19, 2025 |
CVE-2025-10146
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jun 19, 2025 |
CVE-2025-4367
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 15, 2025 |
CVE-2024-8284
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Apr 19, 2025 |
CVE-2025-3404
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires an authenticated author account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 18, 2025 |
CVE-2025-3056
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 16, 2025 |
CVE-2024-13126
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.6
NVDPending
|
| Mar 13, 2025 |
CVE-2025-1785
Download Manager: Filesystem traversal
Download Manager is affected by filesystem traversal. Exploitation requires an authenticated author account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE5.4
NVD8.1
|
| Dec 31, 2024 |
CVE-2024-56217
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD6.3
|
| Dec 20, 2024 |
CVE-2024-10706
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Dec 19, 2024 |
CVE-2024-11768
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 19, 2024 |
CVE-2024-11740
The Download Manager: A security weakness
The Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVD7.3
|
| Oct 30, 2024 |
CVE-2024-8444
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jul 31, 2024 |
CVE-2024-6208
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 13, 2024 |
CVE-2024-2098
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 12, 2024 |
CVE-2024-1766
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD5.4
|
| Jun 12, 2024 |
CVE-2024-5266
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 05, 2024 |
CVE-2024-4001
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 31, 2024 |
CVE-2024-4160
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 17, 2024 |
CVE-2024-32131
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Mar 19, 2024 |
CVE-2024-29114
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 13, 2024 |
CVE-2023-6954
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2023-6785
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 01, 2024 |
CVE-2023-6421
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Jun 09, 2023 |
CVE-2023-2305
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 30, 2023 |
CVE-2023-1524
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| May 02, 2023 |
CVE-2023-1809
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Apr 18, 2023 |
CVE-2022-45836
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.3
NVD6.1
|
| Jan 16, 2023 |
CVE-2022-4476
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Sep 26, 2022 |
CVE-2022-2926
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Sep 06, 2022 |
CVE-2022-2436
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Sep 06, 2022 |
CVE-2022-2431
Download Manager: Code execution
Download Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.1
NVD8.8
|
| Aug 23, 2022 |
CVE-2022-36288
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Aug 23, 2022 |
CVE-2022-34658
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 22, 2022 |
CVE-2022-34347
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.2
NVD8.8
|
| Aug 22, 2022 |
CVE-2022-2362
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Jul 18, 2022 |
CVE-2022-2101
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 17, 2022 |
CVE-2022-2168
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jun 13, 2022 |
CVE-2022-1985
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Apr 11, 2022 |
CVE-2022-0828
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Mar 07, 2022 |
CVE-2021-25087
Download Manager: Sensitive information exposure
Download Manager is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Feb 21, 2022 |
CVE-2021-25069
Download Manager: SQL injection
Download Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Dec 27, 2021 |
CVE-2021-24969
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Nov 01, 2021 |
CVE-2021-24773
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Aug 05, 2021 |
CVE-2021-34639
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Aug 05, 2021 |
CVE-2021-34638
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Sep 03, 2019 |
CVE-2019-15889
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jan 16, 2018 |
CVE-2017-18032
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 07, 2017 |
CVE-2014-9260
basic_settings function in the download manager: A security weakness
basic_settings function in the download manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Jul 07, 2017 |
CVE-2017-2217
Download Manager: An open redirect
Download Manager is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 07, 2017 |
CVE-2017-2216
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Nov 04, 2014 |
CVE-2014-8585
WordPress Download Manager: Filesystem traversal
WordPress Download Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD5.0
|
| Feb 06, 2014 |
CVE-2013-7319
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.3
|