Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Download Manager — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in Download Manager, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Download Manager product, covering specific weakness types associated with its vendor. It collects security advisories, including buffer overflows, remote code execution flaws, and privilege escalation issues recorded over the past five years. Readers can use this resource to track the vendor's published advisories, understand the recurrence of a particular weakness class, and review the product's complete vulnerability history to identify patterns or recurring security gaps in the codebase.

Vendor: W3 Eden, Inc.

CVE ID Title CVSS Severity Published
CVE-2024-11740 Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution CWE-94 7.3 High 2024-12-19
CVE-2024-8444 Download Manager < 3.3.00 - Contributor+ Stored XSS 6.1AI Medium AI 2024-10-30
CVE-2024-6208 Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2024-07-31
CVE-2024-2098 Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary CWE-289 7.5 High 2024-06-13
CVE-2024-1766 Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting CWE-79 4.4 Medium 2024-06-12
CVE-2024-5266 Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes CWE-79 6.4 Medium 2024-06-12
CVE-2024-4001 Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode CWE-79 6.4 Medium 2024-06-05
CVE-2024-4160 Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode CWE-79 6.4 Medium 2024-05-31
CVE-2024-32131 WordPress Download Manager plugin <= 3.2.82 - File Password Lock Bypass vulnerability CWE-200 5.3 Medium 2024-05-17
CVE-2024-29114 WordPress Download Manager plugin <= 3.2.84 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-03-19
CVE-2023-6785 Download Manager <= 3.2.84 - Missing Authorization CWE-284 5.3 Medium 2024-03-13
CVE-2023-6954 Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2024-03-13
CVE-2023-6421 Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak 7.5 - 2024-01-01
CVE-2023-2305 Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2023-06-09
CVE-2023-1524 Download Manager < 3.2.71 - Broken Access Controls 6.5 - 2023-05-30
CVE-2023-1809 Download Manager Pro < 6.3.0 - Unauthenticated Sensitive Information Disclosure 7.5 - 2023-05-02
CVE-2022-45836 WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 Medium 2023-04-18
CVE-2022-4476 Download Manager < 3.2.62 - Contributor+ Stored XSS 5.4 - 2023-01-16
CVE-2022-2926 Download Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path Traversal CWE-22 4.9 - 2022-09-26
CVE-2022-2436 Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization CWE-502 8.8 High 2022-09-06
CVE-2022-2431 Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion CWE-73 8.1 High 2022-09-06
CVE-2022-2362 Download Manager < 3.2.50 - Bypass IP Address Blocking Restriction CWE-79 9.1 - 2022-08-22
CVE-2022-2101 Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting CWE-79 6.4 Medium 2022-07-18
CVE-2022-2168 Download Manager < 3.2.44 - Reflected Cross-Site Scripting CWE-79 6.1 - 2022-07-17
CVE-2022-1985 Download Manager <= 3.2.42 - Reflected Cross-Site Scripting CWE-79 6.1 Medium 2022-06-13
CVE-2022-0828 Download Manager < 3.2.39 - Unauthenticated brute force of files master key 7.5 - 2022-04-11
CVE-2021-25087 Wordpress Download Manager < 3.2.25 - Sensitive Information Disclosure CWE-862 7.5 - 2022-03-07
CVE-2021-25069 WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSS CWE-89 9.8 - 2022-02-21

All 58 known CVE vulnerabilities affecting Download Manager with full Chinese analysis, references, and POCs where available.