WP-DownloadManager
WP-DownloadManager has 10 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 10 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 4 of the records (40%). Other recurring categories include Path Traversal, Absolute Path Traversal.
Every one of the 10 issues recorded for WP-DownloadManager has a vendor fix available, so running the current release closes all known holes.
6 independent researchers contributed these findings, most of them (3) reported by n4ur15. WP-DownloadManager is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-10747WP-DownloadManager <= 1.68.11 - Authenticated (Admin+) Arbitrary File Upload
Read the full analysisVulnerability Records

WP-DownloadManager
Author
Lester Chan
WP-DownloadManager keeps a library of downloadable files, counts how often each one is fetched, and gives you a downloads page, a feed, a widget and a shortcode to put them in front of your readers. Files can live in a folder on your server or anywhere else on the web, and each one can be limited to a role. Features A downloads page with categories, search, sorting and paging. A [download] shortcode, plus a button on both the Visual and Text editors. Per-file permissions, from everyone down to administrators only. Local files, uploads and remote URLs in one library. A downloads RSS feed. A widget for most downloaded, recent downloads and downloads by category. Every piece of markup is a template you can edit. Donations I spent most of my free time creating, updating, maintaining and supporting these plugins, if you really love my plugins and could spare me a couple of bucks, I will really appreciate it. If not feel free to use it without any obligations. Usage To embed a specific file to be downloaded into a post/page, use [download id="2"] where 2 is your file id. To embed multiple files to be downloaded into a post/page, use [download id="1,2,3"] where 1,2,3 are your file ids. To limit the number of embedded downloads shown for each post in a post stream, use the stream_limit option. Example: [download id="2" stream_limit="4"] This will only display the first 4 downloads for the post when rendered in a post stream, and display the full list of downloads when viewing the single post. To sort embedded downloads, use the sort_by and sort_order options. Example: [download id="2" sort_by="file_id" sort_order="asc"] This will sort the embedded downloads by file ID in ascending order. Valid values for sort_by are: file_id, file, file_name, file_size, file_date, and file_hits To choose what to display within the embedded file, use [download id="1" display="both"] where 1 is your file id and both will display both the file name and file description, whereas name will only display the filename. Note that this will overwrite the “Download Embedded File” template you have on the Templates tab. To embed files as well as categories, use [download id="1,2,3" category="4,5,6"] where 1,2,3 are your file id and 4,5,6 are your category ids. If you are using Default Permalinks, the file direct download link will be http://yoursite.com/index.php?dl_id=2. If you are using Nice Permalinks, the file direct download link will be http://yoursite.com/download/2/, where yoursite.com is your WordPress URL and 2 is your file id. The direct download category link will be http://yoursite.com/downloads/?dl_cat=3, where yoursite.com is your WordPress URL, downloads is your Downloads Page name and 3 is your download category id. In order to upload the files straight to the downloads folder, the folder must be writable by the web server. You can specify which folder to be the downloads folder in WP-Admin -> Downloads -> Settings. You can configure everything else in WP-Admin -> Downloads -> Settings, on the Settings and Templates tabs. Downloads Page Go to WP-Admin -> Pages -> Add New Type any title you like in the post’s title area If you ARE using nice permalinks, after typing the title, WordPress will generate the permalink to the page. You will see an ‘Edit’ link just beside the permalink. Click ‘Edit’ and type in downloads in the text field and click ‘Save’. Type [page_download] in the post’s content area. You can also use [page_download category="1"], this will display all downloads in Category ID 1. Click ‘Publish’ Showing Downloads In A Block Two blocks are available in the editor, under Widgets: Download — one file or several, embedded in a post. File IDs and Category IDs in the sidebar each take one id or a comma-separated list, and between them they say everything [download] says: Show chooses between the name with its description and the name alone, and the Order panel carries the sort column, the direction and the limit that applies where the post is one of many in a stream. Downloads Page — the whole library with its categories, search box and paging, the same listing [page_download] produces. Category ID narrows it to one category, and zero lists them all. Both render on the server, so the block preview in the editor is the real listing rather than an approximation, and adding a file updates every post showing it without re-saving anything. The shortcodes still work and are not going anywhere. [download], [download=2], [page_download] and [page_downloads] behave exactly as they always have, and a post already containing one needs no change. The blocks call the same code the shortcodes call, so the two render identically — use whichever suits the post. There is no third block for [page_downloads]. The plural and the singular are one and the same shortcode registered under two tags, so a block for each would be one block under two names — and unlike a shortcode, a block name is written into the post and stays there. The block wraps [page_download]; the plural remains a shortcode you can keep using. Download Stats (With Widgets) Go to WP-Admin -> Appearance -> Widgets The widget name is Downloads. WP-CLI wp downloadmanager list wp downloadmanager list --category=3 --orderby=file_hits --order=desc --limit=10 wp downloadmanager get 3 wp downloadmanager stats wp downloadmanager reset-hits 3 --yes wp downloadmanager delete 3 --yes wp downloadmanager delete 3 --delete-file --yes list and `stats` report what the Downloads screen shows, including the files whose permission is Hidden — this is the library's own inventory, not what a visitor can see. Sizes are in bytes rather than the rounded units the screen prints, because a figure a script is going to compare is worth having exact. reset-hits is the "Reset the hit count to zero" checkbox on Edit File, and touches the counter and nothing else. **`delete --delete-file` deletes the file from the server as well**, which is the checkbox the Delete File screen offers; without it only the row goes. Both ask before doing anything, so a script has to pass `--yes`. There is no create or update: adding and editing a file offer a four-way choice of source — keep the current file, pick one already in the downloads directory, upload one, or name a remote URL — and two of those are a browser handing over a multipart body.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C