Home/Product/w3eden download manager
Product

w3eden download manager

63 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-4367
< 3.3.19
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortc
6.4MEDIUM
CVE-2024-8284
< 3.2.99
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high priv
4.8MEDIUM
CVE-2024-13126
< 3.3.07
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allo
4.6MEDIUM
CVE-2025-1785
< 3.3.09
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via th
5.4MEDIUM
CVE-2024-56217
< 3.3.04
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access
4.3MEDIUM
CVE-2024-10706
< 3.3.03
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high priv
4.8MEDIUM
CVE-2024-11768
< 3.3.04
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper pas
5.3MEDIUM
CVE-2024-11740
< 3.3.04
The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,
7.3HIGH
CVE-2024-8444
< 3.3.00
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scri
5.4MEDIUM
CVE-2024-6208
< 3.2.98
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortc
6.4MEDIUM
CVE-2024-2098
< 3.2.90
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on t
7.5HIGH
CVE-2024-1766
< 3.2.87
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions u
4.4MEDIUM
CVE-2024-5266
< 3.2.94
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package,
6.4MEDIUM
CVE-2024-4001
< 3.2.94
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' sh
6.4MEDIUM
CVE-2024-4160
< 3.2.90
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortc
6.4MEDIUM
CVE-2024-32131
< 3.2.83
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Byp
5.3MEDIUM
CVE-2024-29114
< 3.2.85
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manag
6.5MEDIUM
CVE-2023-6954
<= 3.2.85
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ve
6.4MEDIUM
CVE-2023-6785
< 3.2.85
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all version
5.3MEDIUM
CVE-2023-6421
< 3.2.83
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an inval
7.5HIGH
CVE-2023-2305
< 3.2.71
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form',
6.4MEDIUM
CVE-2023-1524
< 3.2.71
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon vali
6.5MEDIUM
CVE-2023-1809
>= 6.0.0 and < 6.3.0
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attacker
7.5HIGH
CVE-2022-45836
< 3.2.60
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
6.3MEDIUM
CVE-2022-4476
< 3.2.62
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputti
5.4MEDIUM
CVE-2022-2926
< 3.2.55
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users
4.9MEDIUM
CVE-2022-2436
< 3.2.50
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' paramete
8.8HIGH
CVE-2022-2431
<= 3.2.50
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This i
8.1HIGH
CVE-2022-36288
<= 3.2.48
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
5.4MEDIUM
CVE-2022-34658
<= 3.2.48
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <=
5.4MEDIUM
CVE-2022-34347
<= 3.2.48
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
4.2MEDIUM
CVE-2022-2362
< 3.2.50
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE
7.5HIGH
CVE-2022-2101
<= 3.2.46
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file[files][] parameter in versio
6.4MEDIUM
CVE-2022-2168
< 3.2.44
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of t
6.1MEDIUM
CVE-2017-20093
all versions
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function
4.3MEDIUM
CVE-2022-1985
<= 3.2.42
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42.
6.1MEDIUM
CVE-2022-0828
< 3.2.34
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowi
7.5HIGH
CVE-2021-25087
< 3.2.35
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allo
7.5HIGH
CVE-2021-25069
< 3.2.34
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQ
8.8HIGH
CVE-2021-24969
< 3.2.22
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in v
5.4MEDIUM
CVE-2021-24773
< 3.2.16
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them,
4.8MEDIUM
CVE-2021-34639
<= 3.1.24
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a doub
7.5HIGH
CVE-2021-34638
<= 3.1.24
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sens
6.5MEDIUM
CVE-2020-9688
all versions
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary c
7.8HIGH
CVE-2019-8071
all versions
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to p
9.8CRITICAL
CVE-2019-15889
< 2.9.94
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby
6.1MEDIUM
CVE-2017-18032
< 2.9.52
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admi
6.1MEDIUM
CVE-2014-9260
< 2.7.3
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update
8.8HIGH
CVE-2017-2217
<= 2.9.50
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arb
6.1MEDIUM
CVE-2017-2216
<= 2.9.49
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitra
6.1MEDIUM
CVE-2017-3823
all versions
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container befor
8.8HIGH
CVE-2016-3685
<= 2.1.142
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allo
4.7MEDIUM
CVE-2016-3684
<= 2.1.142
SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent at
4.7MEDIUM
CVE-2014-8585
all versions
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary
CVE-2013-7319
<= 2.5.8
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inje
CVE-2012-0980
all versions
SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via
CVE-2010-0189
<= 1.6.2.60
A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download
CVE-2009-2582
<= 2.2.4.3
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web serv
CVE-2008-1770
<= 2.2.3.5
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the downlo
CVE-2007-6339
<= 2.2.0.0
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers
CVE-2007-1892
all versions
Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows
CVE-2007-1891
all versions
Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (Dow
CVE-2006-5856
<= 2.1
Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin