← WordPress Vulnerabilities
WordPress security by component

Download Manager

Download Manager organizes, manages, and delivers downloadable files through WordPress with controlled access and download tracking.

Download Manager (download-manager) is a WordPress plugin with 70 published CVE records in this archive. The latest tracked vulnerability was published Sep 18, 2026; the highest published CVSS base score is 8.8.

Plugin slug: download-manager

CVE-2026-92714: Download Manager: Package duplication bypasses protected-download restrictions

The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata — including protected file references, role-based access restrictions, and password lock settings — into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files. The export states Author-level access, while the matching changelog describes Contributor-level exposure; both identify the same object-authorization failure. Affected versions reported by the CNA: <= 3.3.68. Official changelog review confirms 3.3.69 as a fixed release for this issue.

PublishedSep 18, 2026
Known safe version3.3.69
Published vulnerabilities for download-manager
Safe version
Sep 18, 2026 CVE-2026-92714
Download Manager: Package duplication bypasses protected-download restrictions
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any object-level authorization check against the targeted wpdmpro package ID. This makes it possible for authenticated attackers, with Author-level access and above, to duplicate arbitrary Download Manager packages owned by other users (including administrators), which copies all package metadata — including protected file references, role-based access restrictions, and password lock settings — into an attacker-owned clone that they can then edit to remove restrictions and download the previously protected files. The export states Author-level access, while the matching changelog describes Contributor-level exposure; both identify the same object-authorization failure. Affected versions reported by the CNA: <= 3.3.68. Official changelog review confirms 3.3.69 as a fixed release for this issue.
3.3.69
CVE6.5
NVDPending
Aug 01, 2026 CVE-2026-16685
Download Manager icon attributes let Contributors store JavaScript
Download Manager through 3.3.66 emits the icon attribute of its category shortcode without adequate escaping. A Contributor can store a payload inside the shortcode attribute that bypasses save-time wp_kses_post() and executes when the shortcode renders for a visitor or Administrator.
> 3.3.66
CVE6.4
NVDPending
Aug 01, 2026 CVE-2026-14292
Download Manager package titles let Authors store JavaScript
Download Manager before 3.3.66 does not properly escape a package title in its front-end templates. An Author-or-higher user can save a title containing a script payload, and that JavaScript executes in the browser of any logged-in or anonymous visitor who views a page displaying the package.
3.3.66
CVE5.4
NVDPending
Jul 27, 2026 CVE-2026-14235
Download Manager tokens remain reusable outside the issuing session
Download Manager before 3.3.62 issues temporary download tokens that are not bound to the session that requested them and are not promptly expired. Anyone who obtains a leaked token can reuse it as a long-lived bearer credential to repeatedly download a role-protected or password-protected package without the original user's session.
3.3.62
CVE7.5
NVDPending
Jul 09, 2026 CVE-2026-14343
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.61.
See mitigation notes
CVE6.4
NVDPending
Jul 01, 2026 CVE-2026-13733
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.60.
See mitigation notes
CVE6.4
NVDPending
Apr 10, 2026 CVE-2026-4057
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.51.
See mitigation notes
CVE4.3
NVDPending
Apr 09, 2026 CVE-2026-5357
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.52.
See mitigation notes
CVE6.4
NVDPending
Apr 08, 2026 CVE-2026-39676
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.52.
3.3.53
CVE5.3
NVDPending
Apr 08, 2026 CVE-2026-39615
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.53.
See mitigation notes
CVE5.9
NVDPending
Mar 19, 2026 CVE-2026-2571
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 18, 2026 CVE-2026-1666
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jan 06, 2026 CVE-2025-15364
Download Manager: Privilege escalation or authentication bypass
Download Manager is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.3
NVDPending
Dec 18, 2025 CVE-2025-13498
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 09, 2025 CVE-2025-63070
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 08, 2025 CVE-2025-12177
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 26, 2025 CVE-2025-60093
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Sep 26, 2025 CVE-2025-60092
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 19, 2025 CVE-2025-10146
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jun 19, 2025 CVE-2025-4367
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 15, 2025 CVE-2024-8284
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Apr 19, 2025 CVE-2025-3404
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires an authenticated author account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Apr 18, 2025 CVE-2025-3056
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Mar 16, 2025 CVE-2024-13126
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.6
NVDPending
Mar 13, 2025 CVE-2025-1785
Download Manager: Filesystem traversal
Download Manager is affected by filesystem traversal. Exploitation requires an authenticated author account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.4
NVD8.1
Dec 31, 2024 CVE-2024-56217
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.3
Dec 20, 2024 CVE-2024-10706
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 19, 2024 CVE-2024-11768
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 19, 2024 CVE-2024-11740
The Download Manager: A security weakness
The Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD7.3
Oct 30, 2024 CVE-2024-8444
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jul 31, 2024 CVE-2024-6208
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 13, 2024 CVE-2024-2098
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jun 12, 2024 CVE-2024-1766
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD5.4
Jun 12, 2024 CVE-2024-5266
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 05, 2024 CVE-2024-4001
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 31, 2024 CVE-2024-4160
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 17, 2024 CVE-2024-32131
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD7.5
Mar 19, 2024 CVE-2024-29114
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 13, 2024 CVE-2023-6954
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2023-6785
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 01, 2024 CVE-2023-6421
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jun 09, 2023 CVE-2023-2305
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 30, 2023 CVE-2023-1524
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
May 02, 2023 CVE-2023-1809
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Apr 18, 2023 CVE-2022-45836
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.3
NVD6.1
Jan 16, 2023 CVE-2022-4476
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Sep 26, 2022 CVE-2022-2926
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVD4.9
Sep 06, 2022 CVE-2022-2436
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Sep 06, 2022 CVE-2022-2431
Download Manager: Code execution
Download Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.1
NVD8.8
Aug 23, 2022 CVE-2022-36288
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Aug 23, 2022 CVE-2022-34658
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 22, 2022 CVE-2022-34347
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.2
NVD8.8
Aug 22, 2022 CVE-2022-2362
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Jul 18, 2022 CVE-2022-2101
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 17, 2022 CVE-2022-2168
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jun 13, 2022 CVE-2022-1985
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 11, 2022 CVE-2022-0828
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Mar 07, 2022 CVE-2021-25087
Download Manager: Sensitive information exposure
Download Manager is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVEPending
NVD7.5
Feb 21, 2022 CVE-2021-25069
Download Manager: SQL injection
Download Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD8.8
Dec 27, 2021 CVE-2021-24969
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Nov 01, 2021 CVE-2021-24773
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Aug 05, 2021 CVE-2021-34639
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD8.8
Aug 05, 2021 CVE-2021-34638
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD6.5
Sep 03, 2019 CVE-2019-15889
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 16, 2018 CVE-2017-18032
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Aug 07, 2017 CVE-2014-9260
basic_settings function in the download manager: A security weakness
basic_settings function in the download manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD8.8
Jul 07, 2017 CVE-2017-2217
Download Manager: An open redirect
Download Manager is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVEPending
NVD6.1
Jul 07, 2017 CVE-2017-2216
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Nov 04, 2014 CVE-2014-8585
WordPress Download Manager: Filesystem traversal
WordPress Download Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD5.0
Feb 06, 2014 CVE-2013-7319
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.3