← WordPress Vulnerabilities
WordPress security by component

Download Manager

Download Manager is a WordPress component with 67 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: download-manager

CVE-2026-14235: Download Manager tokens remain reusable outside the issuing session

Download Manager before 3.3.62 issues temporary download tokens that are not bound to the session that requested them and are not promptly expired. Anyone who obtains a leaked token can reuse it as a long-lived bearer credential to repeatedly download a role-protected or password-protected package without the original user's session. The CNA record does not identify the token parameter, route or validation function.

PublishedJul 27, 2026
Known safe version3.3.62
Safe version
Jul 27, 2026 CVE-2026-14235
Download Manager tokens remain reusable outside the issuing session
Download Manager before 3.3.62 issues temporary download tokens that are not bound to the session that requested them and are not promptly expired. Anyone who obtains a leaked token can reuse it as a long-lived bearer credential to repeatedly download a role-protected or password-protected package without the original user's session. The CNA record does not identify the token parameter, route or validation function.
3.3.62
CVE7.5
NVDPending
Jul 09, 2026 CVE-2026-14343
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.61.
> 3.3.61
CVE6.4
NVDPending
Jul 01, 2026 CVE-2026-13733
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.60.
> 3.3.60
CVE6.4
NVDPending
Apr 10, 2026 CVE-2026-4057
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.51.
> 3.3.51
CVE4.3
NVDPending
Apr 09, 2026 CVE-2026-5357
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.52.
> 3.3.52
CVE6.4
NVDPending
Apr 08, 2026 CVE-2026-39676
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.3.52.
3.3.53
CVE5.3
NVDPending
Apr 08, 2026 CVE-2026-39615
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.53.
> 3.3.53
CVE5.9
NVDPending
Mar 19, 2026 CVE-2026-2571
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 18, 2026 CVE-2026-1666
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jan 06, 2026 CVE-2025-15364
Download Manager: Privilege escalation or authentication bypass
Download Manager is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.3
NVDPending
Dec 18, 2025 CVE-2025-13498
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 09, 2025 CVE-2025-63070
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 08, 2025 CVE-2025-12177
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 26, 2025 CVE-2025-60093
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Sep 26, 2025 CVE-2025-60092
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 19, 2025 CVE-2025-10146
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jun 19, 2025 CVE-2025-4367
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 15, 2025 CVE-2024-8284
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Apr 19, 2025 CVE-2025-3404
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires at least author-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Apr 18, 2025 CVE-2025-3056
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Mar 16, 2025 CVE-2024-13126
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.6
NVDPending
Mar 13, 2025 CVE-2025-1785
Download Manager: Filesystem traversal
Download Manager is affected by filesystem traversal. Exploitation requires at least author-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.4
NVD8.1
Dec 31, 2024 CVE-2024-56217
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.3
Dec 20, 2024 CVE-2024-10706
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 19, 2024 CVE-2024-11768
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 19, 2024 CVE-2024-11740
The Download Manager: A security weakness
The Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD7.3
Oct 30, 2024 CVE-2024-8444
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jul 31, 2024 CVE-2024-6208
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 13, 2024 CVE-2024-2098
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jun 12, 2024 CVE-2024-1766
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD5.4
Jun 12, 2024 CVE-2024-5266
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 05, 2024 CVE-2024-4001
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 31, 2024 CVE-2024-4160
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 17, 2024 CVE-2024-32131
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD7.5
Mar 19, 2024 CVE-2024-29114
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 13, 2024 CVE-2023-6954
Download Manager Pro: Cross-site scripting
Download Manager Pro is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2023-6785
Download Manager: A security weakness
Download Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 01, 2024 CVE-2023-6421
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jun 09, 2023 CVE-2023-2305
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 30, 2023 CVE-2023-1524
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
May 02, 2023 CVE-2023-1809
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Apr 18, 2023 CVE-2022-45836
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.3
NVD6.1
Jan 16, 2023 CVE-2022-4476
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Sep 26, 2022 CVE-2022-2926
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVD4.9
Sep 06, 2022 CVE-2022-2436
Download Manager: Code execution
Download Manager is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Sep 06, 2022 CVE-2022-2431
Download Manager: Code execution
Download Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.1
NVD8.8
Aug 23, 2022 CVE-2022-36288
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Aug 23, 2022 CVE-2022-34658
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 22, 2022 CVE-2022-34347
Download Manager: Cross-site request forgery
Download Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.2
NVD8.8
Aug 22, 2022 CVE-2022-2362
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jul 18, 2022 CVE-2022-2101
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 17, 2022 CVE-2022-2168
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jun 13, 2022 CVE-2022-1985
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 11, 2022 CVE-2022-0828
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Mar 07, 2022 CVE-2021-25087
Download Manager: Sensitive information exposure
Download Manager is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVD7.5
Feb 21, 2022 CVE-2021-25069
Download Manager: SQL injection
Download Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Dec 27, 2021 CVE-2021-24969
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Nov 01, 2021 CVE-2021-24773
WordPress Download Manager: Cross-site scripting
WordPress Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Aug 05, 2021 CVE-2021-34639
Download Manager: A security weakness
Download Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD8.8
Aug 05, 2021 CVE-2021-34638
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD6.5
Sep 03, 2019 CVE-2019-15889
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 16, 2018 CVE-2017-18032
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 07, 2017 CVE-2014-9260
basic_settings function in the download manager: A security weakness
basic_settings function in the download manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Jul 07, 2017 CVE-2017-2217
Download Manager: An open redirect
Download Manager is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE6.1
NVD6.1
Jul 07, 2017 CVE-2017-2216
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Nov 04, 2014 CVE-2014-8585
WordPress Download Manager: Filesystem traversal
WordPress Download Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.0
NVD5.0
Feb 06, 2014 CVE-2013-7319
Download Manager: Cross-site scripting
Download Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3