Download Manager

WordPress Download Manager is a plugin that allows users to manage, track, and control file downloads from their WordPress site. It offers features such as password protection, user role control, and download speed and count limits. It can also be used as an e-commerce solution for selling digital products, with options for pricing and licensing. Other features include drag and drop file upload, integrated document viewer, and support for cloud storage services like Google Drive and Dropbox.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Weak configuration vulnerability in Download Manager 3.3.30

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows unauthorized people to access it. This is because there is a hardcoded Cron key used in the functions deleteExpired() and cl...

    Read More
  • Access violation vulnerability in Download Manager 3.3.25

    Fixed

    The Download Manager plugin for WordPress has a security issue that can expose sensitive information. This vulnerability affects all versions up to and including 3.3.24. As a result, unauthenticated ...

    Read More
  • Input validation vulnerability in Download Manager 3.3.24

    Fixed

    A plugin called Download Manager for WordPress has a security issue in versions up to 3.3.24. This is because it doesn't properly check for a special code to prevent fake requests. It could allow som...

    Read More
  • Access violation vulnerability in Download Manager 3.2.82

    Fixed

    . The Download Manager plugin for WordPress has a security issue that could allow anyone to see sensitive information. This problem affects all versions up to 3.2.82. As a result, people who are not l...

    Read More
  • Input validation vulnerability in Download Manager 3.3.23

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows attackers to inject harmful code into web pages by tricking users into clicking on a link. This can occur in versions up to ...

    Read More
  • Input validation vulnerability in Download Manager 3.3.18

    Fixed

    The Download Manager plugin for WordPress has a security issue called Stored Cross-Site Scripting. This can happen when using the plugin's wpdm_user_dashboard feature and affects all versions up to 3...

    Read More
  • Access violation vulnerability in Download Manager 3.3.12

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows unauthorized users to delete important files on the server. This can potentially lead to hackers being able to run harmful c...

    Read More
  • Input validation vulnerability in Download Manager 3.3.12

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows for unauthorized code to be inserted into pages when a user uploads an SVG file. This can be done by attackers who have Auth...

    Read More
  • Access violation vulnerability in Download Manager 3.3.08

    Fixed

    The Download Manager plugin for WordPress has a security issue that affects all versions up to 3.3.08. This can allow attackers with certain levels of access to change files in a different location t...

    Read More
  • Information leakage vulnerability in Download Manager 3.3.06

    Fixed

    The Download Manager plugin for WordPress has a security issue that affects all versions up to 3.3.06. This is because the plugin does not have any restrictions in place for accessing the direct path...

    Read More
  • Access violation vulnerability in Download Manager 3.3.03

    Fixed

    The Download Manager add-on for WordPress has a security issue that allows unauthorized users to access it. This is because it lacks a check to ensure that only certain users can use a specific funct...

    Read More
  • Input validation vulnerability in Download Manager 3.3.02

    Fixed

    The Download Manager plugin for WordPress has a security issue that can allow hackers to inject harmful code into web pages. This can happen if the plugin's admin settings are not properly sanitized....

    Read More
  • Access violation vulnerability in Download Manager 3.3.03

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows unauthorized access to password-protected content. This happens because the password validation process is not done correctl...

    Read More
  • Input validation vulnerability in Download Manager 3.3.03

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows anyone to run shortcodes without proper validation. This means that hackers can use this vulnerability to execute harmful sh...

    Read More
  • Input validation vulnerability in Download Manager Pro 3.2.99

    Fixed

    The Download Manager add-on for WordPress has a security issue that allows hackers to insert harmful code into websites using the plugin's 'wpdm_login_form' feature. This can happen on all versions u...

    Read More
  • Input validation vulnerability in Download Manager 3.2.98

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows hackers to inject harmful code into the website. This can happen if the plugin is not properly sanitized and escaped, making...

    Read More
  • Input validation vulnerability in Download Manager 3.2.97

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows attackers to inject harmful code into pages. This can happen if the attacker has contributor-level access or higher. The iss...

    Read More
  • Vulnerability found in Download Manager

    Fixed

    The Download Manager add-on for WordPress has a security issue that could allow unauthorized people to access sensitive information. This is because the 'protectMediaLibrary' function in all versions...

    Read More
  • Input validation vulnerability in Download Manager 3.2.86

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows hackers to insert harmful code into pages using a user's Display Name. This can only be done by an attacker who has a certai...

    Read More
  • Input validation vulnerability in Download Manager 3.2.92

    Fixed

    The Download Manager Pro plugin for WordPress has a security issue where users with certain permissions can inject harmful code into website pages. This can happen through different shortcodes in the...

    Read More
  • Input validation vulnerability in Download Manager 3.2.93

    Fixed

    The Download Manager plugin for WordPress has a security issue where a hacker can insert harmful code into a webpage using the plugin's 'wpdm_modal_login_form' feature. This can only be done by someo...

    Read More
  • Input validation vulnerability in Download Manager 3.2.90

    Fixed

    A plugin called Download Manager for WordPress has a security issue called Stored Cross-Site Scripting. This means that people with certain access to the plugin can inject harmful code into web pages...

    Read More
  • Input validation vulnerability in Download Manager Pro 3.2.84

    Fixed

    The Download Manager plugin for WordPress is not secure and can be hacked by people with certain levels of access. This could allow them to add harmful code to pages that will run when someone visits...

    Read More
  • Access violation vulnerability in Download Manager 3.2.84

    Fixed

    The Download Manager plugin for WordPress has a security issue that allows anyone to download files that were added using the plugin. This applies to all versions of the plugin, including the latest ...

    Read More
  • Input validation vulnerability in Download Manager 3.2.85

    Fixed

    The Download Manager Pro plugin for WordPress has a security issue that could allow attackers to insert harmful code into pages. This vulnerability affects all versions up to 3.2.85 and is due to a l...

    Read More
  • Access violation vulnerability in Download Manager 3.2.82

    Fixed

    The Download Manager plugin for WordPress has a security issue that can expose sensitive information. This can happen in all versions up to 3.2.82. The problem occurs when the plugin receives an inco...

    Read More
  • Weak configuration vulnerability in Download Manager 3.2.39

    Fixed

    The Download Manager WordPress plugin before version 3.2.39 had a security issue. It used a certain function to generate a ""master key"" for a download. This key could be guessed by an attacker using...

    Read More
  • Authentication vulnerability in Download Manager 3.2.49

    Fixed

    The Download Manager plugin for WordPress is not secure in versions up to 3.2.49 because it can be tricked into allowing access to files that are meant to be blocked. An unauthenticated attacker (some...

    Read More
  • Input validation vulnerability in Download Manager 2.9.45

    Fixed

    The WordPress Download Manager plugin is vulnerable to a type of attack called Cross-Site Request Forgery. This means that in versions up to 2.9.45, attackers who can get a site administrator to clic...

    Read More
  • Access violation vulnerability in Download Manager 3.2.50

    Fixed

    The Download Manager plugin for WordPress has a security issue that affects versions 3.2.50 and below. It allows certain users

    Read More
  • Input validation vulnerability in Download Manager 3.2.34

    Fixed

    The Download Manager WordPress plugin had a security flaw before version 3.2.34 that could be used to inject malicious code into a website. This could also be used to cause a type of attack called Ref...

    Read More
  • Input validation vulnerability in Download Manager 3.1.19

    Fixed

    The WordPress Download Manager plugin for WordPress has a security issue which affects versions before 3.1.19. This issue allows users with Author-level privileges or higher to upload files to the af...

    Read More
  • Access violation vulnerability in Download Manager 2.8.8

    Fixed

    The Download Manager plugin for WordPress could allow unauthenticated attackers to access and download sensitive information from websites. This is because the plugin, in versions up to 2.8.7, does n...

    Read More
  • Input validation vulnerability in Download Manager 2.9.97

    Fixed

    The WordPress Download Manager plugin is vulnerable to Cross-Site Scripting in certain versions. This means that attackers can inject malicious web scripts into the website, which then run in the vic...

    Read More
  • Access violation vulnerability in Download Manager 2.8.8

    Fixed

    The Download Manager plugin for WordPress is a tool that website administrators use to manage downloads. Unfortunately, versions of this plugin up to and including 2.8.7 have a security issue that co...

    Read More
  • Input validation vulnerability in Download Manager 3.2.43

    Fixed

    The Download Manager WordPress plugin before version 3.2.44 had a security flaw that could allow malicious code to be added to the website. This code would be visible to anyone visiting the website

    Read More
  • Input validation vulnerability in Download Manager 2.9.50

    Fixed

    The WordPress Download Manager plugin for WordPress has a security problem in versions up to 2.9.49. If someone is able to get you to do something

    Read More
  • Input validation vulnerability in Download Manager 2.5.8

    Fixed

    The Download Manager plugin for WordPress is not secure in versions up to and including 2.5.8. This means that it's possible for people with bad intentions to inject malicious web scripts into the pl...

    Read More
  • Access violation vulnerability in Download Manager 3.2.35

    Fixed

    The Download Manager WordPress plugin had a security issue before version 3.2.35. Attackers who were not authorised could call certain parts of the plugin's REST API

    Read More
  • Access violation vulnerability in Download Manager 3.2.70

    Fixed

    The Download Manager plugin for WordPress is vulnerable to a security issue in versions 3.2.7.0 or earlier. This plugin allows users to create posts or files that can be protected with a password. Un...

    Read More
  • Input validation vulnerability in Download Manager 3.2.46

    Fixed

    The Download Manager plugin for WordPress has a security issue: it can be used to inject malicious code into the website. This is possible in versions up to

    Read More
  • Input validation vulnerability in Download Manager 2.7.94

    Fixed

    The Download Manager plugin for WordPress is vulnerable to a type of attack, called Stored Cross-Site Scripting, in versions up to and including 2.7.95. This type of attack allows malicious attackers...

    Read More
  • Input validation vulnerability in Download Manager 3.2.70

    Fixed

    The Download Manager plugin for WordPress, up to version 3.2.70, is vulnerable to a type of attack called Stored Cross-Site Scripting. In this attack, an attacker with contributor-level or higher per...

    Read More
  • Input validation vulnerability in Download Manager 3.2.13

    Fixed

    The WordPress Download Manager plugin for WordPress may have a security issue in versions up to and including 3.2.12. This issue is called Cross-Site Request Forgery, and it may occur if nonce valida...

    Read More
  • Input validation vulnerability in Download Manager 3.2.22

    Fixed

    Read More
  • Input validation vulnerability in Download Manager 3.2.43

    Fixed

    The Download Manager plugin for WordPress has a vulnerability in versions up to and including 3.2.43. This vulnerability allows attackers to inject malicious web scripts into pages if they can trick ...

    Read More
  • Input validation vulnerability in Download Manager 2.9.51

    Fixed

    WordPress Download Manager

    Read More
  • Input validation vulnerability in Download Manager 2.9.94

    Fixed

    The WordPress Download Manager plugin before version 2.9.94 had a security vulnerability that allowed malicious code to be inserted into the plugin. This vulnerability could be exploited by using cert...

    Read More
  • Access violation vulnerability in Download Manager 6.3.0

    Fixed

    The Download Manager Pro plugin for WordPress has a security flaw which lets people see sensitive information without permission. This vulnerability exists in versions up to 6.2.9 and it allows an una...

    Read More
  • Input validation vulnerability in Download Manager 3.2.42

    Fixed

    The Download Manager Plugin for WordPress is not secure in versions up to 3.2.42. This is because it does not properly check user input and does not escape what is sent back. The problem is located in...

    Read More
  • Input validation vulnerability in Download Manager 2.9.6

    Fixed

    The WordPress Download Manager plugin is vulnerable to a type of attack called Cross-Site Request Forgery in versions up to 2.9.6. This means that unauthenticated attackers can send malicious links t...

    Read More
  • Input validation vulnerability in Download Manager 3.1.24

    Fixed

    WordPress Download Manager is a plugin used on WordPress websites. In versions 3.1.24 and earlier

    Read More
  • Access violation vulnerability in Download Manager 3.1.23

    Fixed

    The WordPress Download Manager plugin for WordPress is vulnerable to a security issue in versions before 3.1.23. This issue makes it possible for an attacker with low level privileges to perform unau...

    Read More
  • Input validation vulnerability in Download Manager 2.2.2

    Fixed

    The Download Manager plugin for WordPress has a security vulnerability that could allow attackers to inject malicious web scripts into a victim's browser. This vulnerability is present in versions up...

    Read More
  • Access violation vulnerability in Download Manager 2.8.8

    Fixed

    The Download Manager plugin for WordPress has a security vulnerability in versions up to 2.8.7. This vulnerability allows attackers who are not logged in to access and read the files located in a spe...

    Read More
  • Input validation vulnerability in Download Manager 2.7.5

    Fixed

    The Download Manager plugin for WordPress is a program that can be used on websites built with WordPress. Unfortunately, versions of the Download Manager plugin up to, and including, 2.7.4 have a sec...

    Read More
  • Access violation vulnerability in Download Manager 2.7.3

    Fixed

    The download manager plugin for WordPress version 2.7.3 and earlier may allow someone who is remotely logged in to change all of the settings of the WordPress website.

    Read More
  • Access violation vulnerability in Download Manager 3.2.55

    Fixed

    The Download Manager plugin for WordPress contains a security issue that makes it possible for people with administrator-level access to the blog to view and read any file or folder that is not part o...

    Read More
  • Input validation vulnerability in Download Manager 3.1.22

    Fixed

    The WordPress Download Manager plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery in versions before 3.1.22. This is because the plugin does not have the r...

    Read More
  • Output validation vulnerability in Download Manager 3.2.49

    Fixed

    The Download Manager plugin for WordPress has a security issue that could allow people with certain privileges to upload malicious files. If someone with enough access is able to upload the right kind...

    Read More
  • Input validation vulnerability in Download Manager 2.9.51

    Fixed

    The download-manager plugin (a plugin for the website-building software WordPress) released before version 2.9.52 had a security vulnerability which could allow someone to gain access to your website ...

    Read More
  • Input validation vulnerability in Download Manager 3.2.48

    Fixed

    The Download Manager plugin for WordPress

    Read More
  • Input validation vulnerability in Download Manager 2.5.8

    Fixed

    The Download Manager plugin for WordPress (a website creation tool) has a security issue that lets malicious people add dangerous code to it. This code

    Read More
  • Input validation vulnerability in Download Manager 3.2.48

    Fixed

    The Download Manager plugin for WordPress has a security vulnerability in versions up to and including 3.2.48. This means that if someone with the right permissions (such as a contributor or someone w...

    Read More
  • Input validation vulnerability in Download Manager 3.2.53

    Fixed

    The Download Manager plugin for WordPress has a security vulnerability that allows attackers to inject malicious code into webpages. This vulnerability affects all versions of the plugin up to and in...

    Read More
  • Input validation vulnerability in Download Manager 3.1.24

    Fixed

    WordPress Download Manager

    Read More
  • Input validation vulnerability in Download Manager 3.2.48

    Fixed

    The Download Manager plugin for WordPress has a security flaw in versions up to 3.2.48. This flaw allows unauthenticated attackers to make changes to settings on the website if they can trick a site a...

    Read More
  • Input validation vulnerability in Download Manager 3.2.59

    Fixed

    The Download Manager plugin for WordPress versions up to and including 3.2.59 has a security vulnerability that could allow an unauthenticated attacker to inject malicious web scripts into pages. This...

    Read More
  • Input validation vulnerability in Download Manager 3.2.16

    Fixed

    Read More
  • Input validation vulnerability in Download Manager 3.2.61

    Fixed

    The Download Manager plugin for WordPress is vulnerable to a type of malicious attack called Stored Cross-Site Scripting. This type of attack can be used by attackers who have access to certain levels...

    Read More
  • Access violation vulnerability in Download Manager 3.1.18

    Fixed

    The WordPress Download Manager plugin, used with WordPress websites, has a security issue in versions up to 3.1.17. This issue allows unauthorized people to make copies of any download on a vulnerabl...

    Read More