WordPress security by component
Download Manager
Plugin description
Download Manager is a WordPress component with 67 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
download-managerLatest vulnerability
CVE-2026-14235: Download Manager tokens remain reusable outside the issuing session
Download Manager before 3.3.62 issues temporary download tokens that are not bound to the session that requested them and are not promptly expired. Anyone who obtains a leaked token can reuse it as a long-lived bearer credential to repeatedly download a role-protected or password-protected package without the original user's session. The CNA record does not identify the token parameter, route or validation function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-14235
Download Manager tokens remain reusable outside the issuing session
Download Manager before 3.3.62 issues temporary download tokens that are not bound to the session that requested them and are not promptly expired. Anyone who obtains a leaked token can reuse it as a long-lived bearer credential to repeatedly download a role-protected or password-protected package without the original user's session. The CNA record does not identify the token parameter, route or validation function.
|
3.3.62 |
CVE7.5
NVDPending
|
| Jul 09, 2026 |
CVE-2026-14343
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.61.
|
> 3.3.61 |
CVE6.4
NVDPending
|
| Jul 01, 2026 |
CVE-2026-13733
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.60.
|
> 3.3.60 |
CVE6.4
NVDPending
|
| Apr 10, 2026 |
CVE-2026-4057
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.51.
|
> 3.3.51 |
CVE4.3
NVDPending
|
| Apr 09, 2026 |
CVE-2026-5357
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.52.
|
> 3.3.52 |
CVE6.4
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39676
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.52.
|
3.3.53 |
CVE5.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39615
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.53.
|
> 3.3.53 |
CVE5.9
NVDPending
|
| Mar 19, 2026 |
CVE-2026-2571
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1666
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jan 06, 2026 |
CVE-2025-15364
Download Manager: Privilege escalation or authentication bypass
Download Manager is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE7.3
NVDPending
|
| Dec 18, 2025 |
CVE-2025-13498
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 09, 2025 |
CVE-2025-63070
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 08, 2025 |
CVE-2025-12177
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 26, 2025 |
CVE-2025-60093
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 26, 2025 |
CVE-2025-60092
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 19, 2025 |
CVE-2025-10146
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jun 19, 2025 |
CVE-2025-4367
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 15, 2025 |
CVE-2024-8284
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Apr 19, 2025 |
CVE-2025-3404
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires at least author-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 18, 2025 |
CVE-2025-3056
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 16, 2025 |
CVE-2024-13126
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.6
NVDPending
|
| Mar 13, 2025 |
CVE-2025-1785
Download Manager: Filesystem traversal
Download Manager is affected by filesystem traversal. Exploitation requires at least author-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE5.4
NVD8.1
|
| Dec 31, 2024 |
CVE-2024-56217
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD6.3
|
| Dec 20, 2024 |
CVE-2024-10706
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Dec 19, 2024 |
CVE-2024-11768
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 19, 2024 |
CVE-2024-11740
The Download Manager: A security weakness
The Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVD7.3
|
| Oct 30, 2024 |
CVE-2024-8444
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jul 31, 2024 |
CVE-2024-6208
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 13, 2024 |
CVE-2024-2098
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 12, 2024 |
CVE-2024-1766
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD5.4
|
| Jun 12, 2024 |
CVE-2024-5266
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 05, 2024 |
CVE-2024-4001
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 31, 2024 |
CVE-2024-4160
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 17, 2024 |
CVE-2024-32131
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Mar 19, 2024 |
CVE-2024-29114
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 13, 2024 |
CVE-2023-6954
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2023-6785
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 01, 2024 |
CVE-2023-6421
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Jun 09, 2023 |
CVE-2023-2305
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 30, 2023 |
CVE-2023-1524
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| May 02, 2023 |
CVE-2023-1809
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Apr 18, 2023 |
CVE-2022-45836
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.3
NVD6.1
|
| Jan 16, 2023 |
CVE-2022-4476
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Sep 26, 2022 |
CVE-2022-2926
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Sep 06, 2022 |
CVE-2022-2436
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Sep 06, 2022 |
CVE-2022-2431
Download Manager: Code execution
Download Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.1
NVD8.8
|
| Aug 23, 2022 |
CVE-2022-36288
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Aug 23, 2022 |
CVE-2022-34658
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 22, 2022 |
CVE-2022-34347
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.2
NVD8.8
|
| Aug 22, 2022 |
CVE-2022-2362
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Jul 18, 2022 |
CVE-2022-2101
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 17, 2022 |
CVE-2022-2168
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jun 13, 2022 |
CVE-2022-1985
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Apr 11, 2022 |
CVE-2022-0828
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Mar 07, 2022 |
CVE-2021-25087
Download Manager: Sensitive information exposure
Download Manager is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Feb 21, 2022 |
CVE-2021-25069
Download Manager: SQL injection
Download Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Dec 27, 2021 |
CVE-2021-24969
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Nov 01, 2021 |
CVE-2021-24773
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Aug 05, 2021 |
CVE-2021-34639
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Aug 05, 2021 |
CVE-2021-34638
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Sep 03, 2019 |
CVE-2019-15889
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jan 16, 2018 |
CVE-2017-18032
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 07, 2017 |
CVE-2014-9260
basic_settings function in the download manager: A security weakness
basic_settings function in the download manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Jul 07, 2017 |
CVE-2017-2217
Download Manager: An open redirect
Download Manager is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jul 07, 2017 |
CVE-2017-2216
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Nov 04, 2014 |
CVE-2014-8585
WordPress Download Manager: Filesystem traversal
WordPress Download Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE5.0
NVD5.0
|
| Feb 06, 2014 |
CVE-2013-7319
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|