Download Manager

Explore Download Manager vulnerabilities across all versions. Currently tracking 81 known vulnerabilities, including severity, impact, and patch status.

01234567891010.02.2010Today07.12.20135.3Download Manager <= 2.5.8 - Cross-Site Scripting CVSS 5.3 · 07.12.201308.12.20137.2Download Manager < 2.5.9 - Stored Cross-Site Scripting CVSS 7.2 · 08.12.201301.08.20146.1Download Manager <= 2.2.2 - Cross-Site Scripting CVSS 6.1 · 01.08.201424.11.20148.1WordPress Download Manager <= 2.7.2 - Authenticated Arbitrary Options Update CVSS 8.1 · 24.11.201415.12.20149.8WordPress Download Manager <= 2.7.4 - Remote Code Execution CVSS 9.8 · 15.12.201416.07.20156.4WordPress Download Manager <= 2.7.94 - Stored Cross-Site Scripting CVSS 6.4 · 16.07.201519.01.20169.1Download Manager <= 2.8.7 - Missing Authorization CVSS 9.1 · 19.01.20165.3Download Manager <= 2.8.7 - Sensitive Information Disclosure via Directory Listing CVSS 5.3 · 19.01.20166.5Download Manager <= 2.8.7 - Privilege Escalation CVSS 6.5 · 19.01.201601.03.20178.8WordPress Download Manager <= 2.9.45 - Cross-Site Request Forgery CVSS 8.8 · 01.03.201713.06.20176.1WordPress Download Manager <= 2.9.49 - Reflected Cross-Site Scripting CVSS 6.1 · 13.06.201716.06.20176.1WordPress Download Manager <= 2.9.51 - Cross-Site Scripting CVSS 6.1 · 16.06.201713.07.20176.1WordPress Download Manager < 2.9.51 - Open Redirect CVSS 6.1 · 13.07.201709.01.20186.3WordPress Download Manager <= 2.9.6 - Cross-Site Request Forgery CVSS 6.3 · 09.01.201813.04.20196.1WordPress Download Manager <= 2.9.93 - Cross-Site Scripting CVSS 6.1 · 13.04.201916.06.20196.1WordPress Download Manager <= 2.9.96 - Cross-Site Scripting CVSS 6.1 · 16.06.201916.04.20215.3Download Manager <= 3.1.17 - Missing Authorization CVSS 5.3 · 16.04.202130.04.20218.8WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery CVSS 8.8 · 30.04.20218.8WordPress Download Manager < 3.1.19 - Arbitrary File Upload CVSS 8.8 · 30.04.20216.3WordPress Download Manager < 3.1.23 - Arbitrary Asset Manager Usage CVSS 6.3 · 30.04.202129.07.20217.5WordPress Download Manager <= 3.1.24 - Authenticated File Upload CVSS 7.5 · 29.07.20216.5WordPress Download Manager <= 3.1.24 - Cross-Site Scripting CVSS 6.5 · 29.07.202109.08.20217.1WordPress Download Manager <= 3.2.12 - Cross-Site Request Forgery CVSS 7.1 · 09.08.202129.09.20215.5WordPress Download Manager <= 3.2.15 - Cross-Site Scripting CVSS 5.5 · 29.09.202129.11.20216.4WordPress Download Manager <= 3.2.21 - Cross-Site Scripting CVSS 6.4 · 29.11.202120.01.20228.8WordPress Download Manager <= 3.2.33 - Authenticated SQL Injection CVSS 8.8 · 20.01.202202.02.20227.5Download Manager <= 3.2.34 - Sensitive Information Disclosure CVSS 7.5 · 02.02.202216.03.20227.5Download Manager <= 3.2.38 - Unauthenticated Brute Force of File Master Key CVSS 7.5 · 16.03.202202.06.20226.1Download Manager <= 3.2.42 - Reflected Cross-Site Scripting CVSS 6.1 · 02.06.202221.06.20226.4Download Manager <= 3.2.46 - Contributor+ Cross-Site Scripting CVSS 6.4 · 21.06.202223.06.20226.1Download Manager <= 3.2.43 - Reflected Cross-Site Scripting CVSS 6.1 · 23.06.202227.06.20226.1Download Manager <= 3.2.43 - Reflected Cross-Site Scripting CVSS 6.1 · 27.06.202206.07.20225.4Download Manager <= 3.2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 5.4 · 06.07.202227.07.20228.8Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion CVSS 8.8 · 27.07.202201.08.20225.3Download Manager <= 3.2.49 - IP Blocking Bypass CVSS 5.3 · 01.08.202202.08.20228.8Download Manager <= 3.2.48 - Cross-Site Request Forgery CVSS 8.8 · 02.08.20228.8Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings Update CVSS 8.8 · 02.08.202204.08.20226.1Download Manager <= 3.2.53 - Reflected Cross-Site Scripting CVSS 6.1 · 04.08.202217.08.20228.8Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization CVSS 8.8 · 17.08.202205.09.20224.9Download Manager <= 3.2.54 - Authenticated (Admin+) Path Traversal CVSS 4.9 · 05.09.202229.11.20226.1Download Manager <= 3.2.59 - Refleced Cross-Site Scripting CVSS 6.1 · 29.11.202220.12.20226.4Download Manager <= 3.2.61 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 20.12.202210.04.20235.3Download Manager Pro <= 6.2.9 - Unauthenticated Information Disclosure CVSS 5.3 · 10.04.202308.05.20234.3Download Manager <= 3.2.70 - Insufficient Authorization to Information Disclosure CVSS 4.3 · 08.05.202312.05.20236.4Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 12.05.202329.11.20235.3Download Manager <= 3.2.82 - Unauthenticated Password Leak CVSS 5.3 · 29.11.202328.02.20246.4Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 28.02.20245.3Download Manager <= 3.2.84 - Missing Authorization CVSS 5.3 · 28.02.202416.03.20246.4Download Manager <= 3.2.84 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 16.03.202430.05.20246.4Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode CVSS 6.4 · 30.05.202404.06.20246.4Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode CVSS 6.4 · 04.06.202411.06.20244.4Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting CVSS 4.4 · 11.06.20246.4Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes CVSS 6.4 · 11.06.202412.06.20247.5Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary CVSS 7.5 · 12.06.202430.07.20246.4Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 30.07.202423.09.20244.4Download Manager <= 3.2.98 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 23.09.202409.10.20246.4Download Manager <= 3.2.99 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 09.10.202429.11.20244.4Download Manager <= 3.3.02 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 29.11.202418.12.20247.3Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution CVSS 7.3 · 18.12.20245.3Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files CVSS 5.3 · 18.12.202419.12.20244.3Download Manager <= 3.3.03 - Missing Authorization CVSS 4.3 · 19.12.202417.01.20255.3Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory CVSS 5.3 · 17.01.202512.03.20255.4Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite CVSS 5.4 · 12.03.202517.04.20255.4Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CVSS 5.4 · 17.04.202518.04.20258.8Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion CVSS 8.8 · 18.04.202518.06.20256.4Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode CVSS 6.4 · 18.06.202518.09.20256.1Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter CVSS 6.1 · 18.09.202526.09.20254.3Download Manager <= 3.3.24 - Cross-Site Request Forgery CVSS 4.3 · 26.09.20255.3Download Manager <= 3.3.25 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 26.09.202530.09.20254.3Download Manager <= 3.3.32 - Authenticated (Subscriber+) Information Exposure CVSS 4.3 · 30.09.202507.11.20255.3Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key CVSS 5.3 · 07.11.202517.12.20254.3Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure CVSS 4.3 · 17.12.202505.01.20267.3Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword CVSS 7.3 · 05.01.202610.02.20266.4Download Manager <= 3.3.53 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 6.4 · 10.02.202617.02.20266.1Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter CVSS 6.1 · 17.02.202619.02.20265.3Download Manager <= 3.3.52 - Missing Authorization CVSS 5.3 · 19.02.202618.03.20264.3Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter CVSS 4.3 · 18.03.202608.04.20266.4Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVSS 6.4 · 08.04.202609.04.20264.3Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal CVSS 4.3 · 09.04.202630.06.20266.4Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute CVSS 6.4 · 30.06.202608.07.20266.4Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes CVSS 6.4 · 08.07.2026

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage100%
Open

0

Fixed

81

Get automatic notifications for all Download Manager vulnerabilities before they are exploited.

Vulnerability Records

81 records
2026-07-08 18:12CVE-2026-14343
6.4
Medium
Wordfence PRISMYes
2026-06-30 18:55CVE-2026-13733
6.4
Medium
Wordfence PRISMYes
2026-04-09 12:00CVE-2026-4057
4.3
Medium
Or BenitYes
2026-04-08 13:33CVE-2026-5357
6.4
Medium
zaimYes
2026-03-18 00:00CVE-2026-2571
4.3
Medium
Quốc Huy (jtwings)Yes
2026-02-19 00:00CVE-2026-39676
5.3
Medium
Steven JulianYes
2026-02-17 17:51CVE-2026-1666
6.1
Medium
Jack TaylorYes
2026-02-10 00:00CVE-2026-39615
6.4
Medium
hhhaiYes
2026-01-05 13:11CVE-2025-15364
7.3
High
Drew Webber (mcdruid)Yes
2025-12-17 00:00CVE-2025-13498
4.3
Medium
type5afeYes
Showing 1–10 of 81 reports
Download Manager banner
Latestv3.3.66

Download Manager

Shahjada

Author

Shahjada

4.1(1,002)
82/100
Last Updated
2026-07-16 (13d ago)
Active Installs
100,000+
Downloads
11,303,953
Requires WP
5.3+
Requires PHP
0+
Tested up to
WP 7.0.2
Created
2010-02-10 (17y ago)

WordPress Download Manager is a Files/Documents Management Plugin designed to manage, track, and control file downloads from your WordPress Site. You can use passwords and user roles to control access to your files, manage download speeds, and limit the number of downloads per user. It also offers features such as Captcha Lock or IP Block to block bots, unwanted users, or spammers. You may even require users to agree to your terms and conditions before downloading. Need to sell digital products? You may use WordPress Download Manager as a complete e-Commerce Solution for selling digital products. Simply put a price when you need to sell a digital item. You also may use license ( ex: Simple, Extended, Unlimited ) based prices for a product. Users can directly download free items and when an item has a price user will have to go through cart & checkout. WordPress Download Manager has the easiest checkout option to give the user better experience in purchasing an item and which always increase the probability of successful completion of an order. Features Custom post type and taxonomy, adding a download is just like creating a post Drag and Drop File Upload Chunk upload support to override http max upload limit Attach file directly from your server using server file browser Media library file protection Integrated document viewer ( DOC, PDF and POWERPOINT ) Quick add panel with tinymce editor button to create and insert a download easily when you are editing a post or page Google Drive support to store your files in Google drive ( 15 GB of space for free) DropBox support to store your files in DropBox ( 2 GB of space for free ) Box.com support to store your files in Box.com ( 10 GB of space for free ) OneDrive support to store your files in onedrive.live.com ( 15 GB of space for free ) Option to “Open in Browser” or “Download” files ( PDFs or images ) Control who can access to download Category level access control Download speed control Password protection CAPTCHA protection Ad blocker detection IP block option to prevent bot downloads or downloads from unwanted IP addresses Download logs to check who is downloading which file from where and when Terms protection – Agree with Terms & Conditions before download Download counter to see total download count for each file Custom download link icon File type icon support Full Featured User Dashboard ( use short-code [wpdm_user_dashboard] ) Custom front-end login / signup form short-code Custom oEmbed template Responsive DataTable support ( use short-code [wpdm_all_packages jstable=1 items_per_page=20] ) Searching and Sorting Option Custom link label Short-code for download link Short-code for direct link to downloadable file [wpdm_direct_link id=file_id_required link_label=any_text_optional] Widget for new files Widget for top downloads Widget for searching downloads Multi-level Categories Custom TinyMce Button Category embed short-code Advanced server file browser Complete category and file tree using a simple short-code [wpdm_tree] MP4 video upload and play support Video file download protection, allow visitors to play but block download Translation Ready Digital Asset Manager Server file manager Create new file and folder easily Move, copy, edit files Integrated file editor with syntax highlights Asset shortcode to embed a file/asset easily in a page or post Upload, Download and Delete operations Video and audio preview/play Digital Asset Manager ( Pro Features ) File tagging Sharable link generator Bookmarking, Comments and discussions Front-end asset management Custom asset metadata Asset archive and version management Complete Digital Store Solution: Use Premium Package – Complete Digital Store Solution Add-on (free) if you need to sell your digital items. The add-on has all features you will ever need to build a perfect online shop for your digital downloads: Single Click Activation ( Auto-install & Activate ) Sell Digital Products Securely Easy Administration PayPal Integrated User-role Based Discount Management Coupon Management Sales Tax Save Cart and Checkout Later Email Saved Cart Product & Price Variations ( License Based Pricing / Sell Extra Gigs with Product ) Promotional Pricing for Your Digital Products “Pay As You Want” pricing Invoice Generation Easiest Checkout System Guest Checkout and Guest Download Order expiration option ( Like 1 year support & update access, then expire ) Auto-renew order option ( Accept Recurring Payment for Orders ) Easy Order Management Sales Notifications via Email Sales Notification Directly in Your Mobile with Push Message Very Detailed Sales Reports Order Notes & Messaging System Extended Product Licensing System License Level Pricing Easy to implement license API for license system integration Full-featured Digital Products Marketplace with Front-end product submission & payout management ( This Feature Requires WPDM v4+ ) Sell individual files ( like single song from an album ) ( This Feature Requires WPDM v4+ ) and much more… Gutenberg Blocks Gutenberg Blocks for gutenberg editor Gutenberg Blocks and Page Layouts – Attire Blocks Elementor Addons Download Manager Addons for Elementor – Use the plugin if you are using Elementor Website Builder. The plugin provides elementor addons for all wordpress download manager shortcodes you were writing manually. Google Drive Use Google Drive Explorer add-on ( free ) to store your files in google drive and link with download manager, get 15 GB free storage space and save your server bandwidth DropBox Use DropBox Explorer add-on ( free ) to store your files in dropbox and link with download manager, get 2 GB free storage space and save your server bandwidth Box.com Use Box.com Explorer add-on ( free ) to store your files in Box.com and link with download manager, get 10 GB free storage space and save your server bandwidth OneDrive Use OneDrive Explorer add-on ( free ) to store your files in Microsoft OneDrive and link with download manager, get 15 GB free storage space and save your server bandwidth pCloud Use pCloud Connector add-on ( premium ) to store your files in pCloud and link with download manager, get 10 GB free storage space and save your server bandwidth Add-ons Download and Install following free add-on to add additional features as per your need Advanced Tiny-Mce Button for editor button to generate short-codes Extended Short-codes for tree view ( [wpdm_tree] ), slider ( [wpdm_slider] ) & carousel ( [wpdm_carousel] ) WPDM Image Button to replace download link label with a custom designed image WPDM Button Templates for pre-designed colorful button styles Mobile Apps Check download stats and get a push notification when someone downloads, install: WPDM API – install this add-on on your site and configure API key WPDM for Android – Install the app on your android phone WPDM for iOS – Check download and sales stats directly from your iPhone or iPad Free Themes Attire – perfect theme for any site like blog, portfolio, photography, stock image, music, video archive, software download directory, ecommerce, and it is free. More Themes & Add-ons Add-ons – 100+ add-ons Themes – Themes Specially Optimized for Download Manager External Service Disclosures This plugin utilizes external services to enhance its functionality. Please review the following disclosures regarding the use of these services: Google reCAPTCHA This plugin may utilize Google reCAPTCHA to enhance security by protecting against spam and unauthorized access. Google reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service, which you can review at https://policies.google.com/privacy and https://policies.google.com/terms, respectively. Microsoft Office Doc Preview Our plugin provides the ability to preview Microsoft Office documents for user convenience. This feature may rely on Microsoft services. Users may be subject to Microsoft’s privacy policies and terms when accessing and previewing Office documents through this plugin. Please consult Microsoft’s Privacy Statement and Terms of Use for further information. Google Doc Preview This plugin may offer Google Doc preview functionality for certain file types. Users may interact with Google’s services during the preview process. Google’s Privacy Policy and Terms of Service apply when using this feature. You can find these policies at https://policies.google.com/privacy and https://policies.google.com/terms. By using this plugin, you acknowledge and agree to the terms and policies of these external services as outlined above.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C