All 5 CVE vulnerabilities found in Download Plugin, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-6586 | Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload CWE-434 | 7.2 | High | 2025-07-04 |
| CVE-2024-9829 | Download Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download CWE-862 | 6.5 | Medium | 2024-10-23 |
| CVE-2022-36345 | WordPress Download Plugin Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 | 4.3 | Medium | 2023-05-28 |
| CVE-2021-25059 | Download Plugin < 2.0.0 - Subscriber+ Website Download | 6.5 | - | 2022-11-28 |
| CVE-2021-24703 | Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation CWE-732 | 6.5 | - | 2021-11-23 |
All 5 known CVE vulnerabilities affecting Download Plugin with full Chinese analysis, references, and POCs where available.