W3Eden Download Manager vulnerabilities

48 known vulnerabilities affecting w3eden/download_manager.

Total CVEs
48
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
HIGH16MEDIUM32

Vulnerabilities

Page 3 of 3
CVE-2021-34638MEDIUMCVSS 6.5≤ 3.1.242021-08-05
CVE-2021-34638 [MEDIUM] CWE-22 CVE-2021-34638: Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Cont Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension
nvd
CVE-2019-15889MEDIUMCVSS 6.1PoCfixed in 2.9.942019-09-03
CVE-2019-15889 [MEDIUM] CWE-79 CVE-2019-15889: The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
nvd
CVE-2017-18032MEDIUMCVSS 6.1fixed in 2.9.522018-01-16
CVE-2017-18032 [MEDIUM] CWE-79 CVE-2017-18032: The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_gener The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
nvd
CVE-2014-9260HIGHCVSS 8.8PoCfixed in 2.7.32017-08-07
CVE-2014-9260 [HIGH] CVE-2014-9260: The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
nvd
CVE-2017-2216MEDIUMCVSS 6.1≤ 2.9.492017-07-07
CVE-2017-2216 [MEDIUM] CWE-79 CVE-2017-2216: Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remo Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2017-2217MEDIUMCVSS 6.1≤ 2.9.502017-07-07
CVE-2017-2217 [MEDIUM] CWE-601 CVE-2017-2217: Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote atta Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2014-8585MEDIUMCVSS 5.0v1.1v1.2+102 more2014-11-04
CVE-2014-8585 [MEDIUM] CWE-59 CVE-2014-8585: Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remo Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
nvd
CVE-2013-7319MEDIUMCVSS 4.3PoC≤ 2.5.8v2.5.0+7 more2014-02-06
CVE-2013-7319 [MEDIUM] CWE-79 CVE-2013-7319: Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress a Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
nvd
W3Eden Download Manager vulnerabilities | cvebase