← WordPress Vulnerabilities
WordPress security by component

WP-DownloadManager

WP-DownloadManager is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Feb 18, 2026; the highest CVE/CNA score is 7.2.

Plugin slug: wp-downloadmanager

CVE-2026-2426: WP-DownloadManager: Filesystem traversal

WP-DownloadManager is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedFeb 18, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 18, 2026 CVE-2026-2426
WP-DownloadManager: Filesystem traversal
WP-DownloadManager is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending
Feb 18, 2026 CVE-2026-2419
WP-DownloadManager: Filesystem traversal
WP-DownloadManager is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE2.7
NVDPending
Sep 26, 2025 CVE-2025-10747
WP-DownloadManager: Dangerous file upload
WP-DownloadManager is affected by dangerous file upload. Exploitation requires at least administrator-level access. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.2
NVDPending
Jun 11, 2025 CVE-2025-4799
WP-DownloadManager: Code execution
WP-DownloadManager is affected by code execution. Exploitation requires at least administrator-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Jun 11, 2025 CVE-2025-4798
WP-DownloadManager: Filesystem traversal
WP-DownloadManager is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Oct 06, 2024 CVE-2024-47341
WP-DownloadManager: Cross-site scripting
WP-DownloadManager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Mar 25, 2022 CVE-2022-25606
Wp Downloadmanager: Cross-site scripting
Wp Downloadmanager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD5.4
Mar 18, 2022 CVE-2022-25605
Wp Downloadmanager: Cross-site scripting
Wp Downloadmanager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD5.4
Mar 18, 2022 CVE-2021-44760
Wp Downloadmanager: Cross-site scripting
Wp Downloadmanager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD5.4
Jul 07, 2021 CVE-2020-24141
Wp Downloadmanager: Server-side request forgery
Wp Downloadmanager is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.3
NVD5.3
Apr 19, 2013 CVE-2013-2697
Wp Downloadmanager: Cross-site scripting
Wp Downloadmanager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.8
NVD6.8