Download Manager
Download Manager has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10.
The most common weakness is Improper Access Control, behind 1 of the records (50%). Other recurring categories include Improper Authorization.
Every one of the 2 issues recorded for Download Manager has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Download Manager is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.5.2.
CVE-2024-32131Download Manager <= 3.2.82 - Password Protected File Bypass
Read the full analysisVulnerability Records

Download Manager
Author
n4nirob
This is a free download manager plugin. Downloadmanager, A very simple WordPress plugin to show your data from a specific data table. You can store Album name, Title, Author name, Category name, Download link from plugin menu. Also you can show any categories data in any page in your site. Very simple, easy wordpress download manager plugin. Support Features Actions: save any quantity of the category data. Description: You can store Album name, Title, Author name, Category name, Download link from plugin menu. Actions: Possibility to load any number of data to each category in the post. Technical support Dear users, if you have any questions or propositions regarding our plugins please feel free to contact. You may contact through mail support@3jon.com Please note that we accept requests in English only.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C