Vulnerabilities > Wpdownloadmanager

DATE CVE VULNERABILITY TITLE RISK
2024-11-18 CVE-2024-52435 SQL Injection vulnerability in Wpdownloadmanager Premium Packages - Sell Digital products Securely
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in W3 Eden, Inc.
network
low complexity
wpdownloadmanager CWE-89
7.2
2024-06-05 CVE-2024-4001 Cross-site Scripting vulnerability in Wpdownloadmanager Download Manager
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpdownloadmanager CWE-79
5.4
2023-08-12 CVE-2023-4293 Unspecified vulnerability in Wpdownloadmanager Premium Packages - Sell Digital products Securely
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function.
network
low complexity
wpdownloadmanager
6.5
2023-05-03 CVE-2023-22713 Unspecified vulnerability in Wpdownloadmanager Gutenberg Blocks for Wordpress Download Manager
Auth.
network
low complexity
wpdownloadmanager
5.4