Vulnerabilities > Wpdownloadmanager > Download Manager > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-19 CVE-2024-11740 Code Injection vulnerability in Wpdownloadmanager Download Manager
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03.
network
low complexity
wpdownloadmanager CWE-94
7.3
2023-05-02 CVE-2023-1809 Unspecified vulnerability in Wpdownloadmanager Download Manager 6.0.0
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
network
low complexity
wpdownloadmanager
7.5
2022-02-21 CVE-2021-25069 Unspecified vulnerability in Wpdownloadmanager Download Manager
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
network
low complexity
wpdownloadmanager
8.8