Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Download Manager — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in Download Manager, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Download Manager product, covering specific weakness types associated with its vendor. It collects security advisories, including buffer overflows, remote code execution flaws, and privilege escalation issues recorded over the past five years. Readers can use this resource to track the vendor's published advisories, understand the recurrence of a particular weakness class, and review the product's complete vulnerability history to identify patterns or recurring security gaps in the codebase.

Vendor: W3 Eden, Inc.

CVE ID Title CVSS Severity Published
CVE-2026-86610 Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon - - 2026-10-01
CVE-2026-86609 Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription - - 2026-09-27
CVE-2026-92714 Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter CWE-639 6.5 Medium 2026-09-18
CVE-2026-16685 Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute CWE-79 6.4 Medium 2026-08-01
CVE-2026-14292 WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title - - 2026-08-01
CVE-2026-14235 WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key - - 2026-07-27
CVE-2026-14343 Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes CWE-79 6.4 Medium 2026-07-09
CVE-2026-13733 Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute CWE-79 6.4 Medium 2026-07-01
CVE-2026-4057 Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal CWE-862 4.3 Medium 2026-04-10
CVE-2026-5357 Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CWE-79 6.4 Medium 2026-04-09
CVE-2026-39676 WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-04-08
CVE-2026-39615 WordPress Download Manager plugin <= 3.3.53 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2026-04-08
CVE-2026-2571 Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter CWE-200 4.3 Medium 2026-03-19
CVE-2026-1666 Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter CWE-79 6.1 Medium 2026-02-18
CVE-2025-15364 Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword CWE-353 7.3 High 2026-01-06
CVE-2025-13498 Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure CWE-862 4.3 Medium 2025-12-18
CVE-2025-63070 WordPress Download Manager plugin <= 3.3.32 - Sensitive Data Exposure vulnerability CWE-497 4.3 Medium 2025-12-09
CVE-2025-12177 Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key CWE-321 5.3 Medium 2025-11-08
CVE-2025-60093 WordPress Download Manager Plugin <= 3.3.24 - Cross Site Request Forgery (CSRF) Vulnerability CWE-352 4.3 Medium 2025-09-26
CVE-2025-60092 WordPress Download Manager Plugin <= 3.3.25 - Sensitive Data Exposure Vulnerability CWE-497 5.3 Medium 2025-09-26
CVE-2025-10146 Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter CWE-79 6.1 Medium 2025-09-19
CVE-2025-4367 Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode CWE-80 6.4 Medium 2025-06-19
CVE-2024-8284 Download Manager <= 3.2.98 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2025-3404 Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion CWE-22 8.8 High 2025-04-19
CVE-2025-3056 Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 5.4 Medium 2025-04-18
CVE-2024-13126 Download Manager < 3.3.07 - Unauthenticated Data Exposure 7.5 - 2025-03-16
CVE-2025-1785 Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite CWE-22 5.4 Medium 2025-03-13
CVE-2024-56217 WordPress Download Manager plugin <= 3.3.03 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-12-31
CVE-2024-10706 Download Manager < 3.3.03 - Admin+ Stored XSS 4.8 - 2024-12-20
CVE-2024-11768 Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files CWE-285 5.3 Medium 2024-12-19

All 58 known CVE vulnerabilities affecting Download Manager with full Chinese analysis, references, and POCs where available.