Wp Downloadmanager Project
wp-downloadmanager_project
6 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wp Downloadmanager Project 1Wp Downloadmanager Jul 9, 2025 Jun 11, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it pos...Show more |
1Wp Downloadmanager Project 1Wp Downloadmanager Jul 9, 2025 Jun 11, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storin...Show more |
1Wp Downloadmanager Project 1Wp Downloadmanager Nov 21, 2024 Mar 25, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_ur...Show more |
1Wp Downloadmanager Project 1Wp Downloadmanager Nov 21, 2024 Mar 18, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_u...Show more |
1Wp Downloadmanager Project 1Wp Downloadmanager Nov 21, 2024 Mar 18, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions. |
1Wp Downloadmanager Project 1Wp Downloadmanager Nov 21, 2024 Jul 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-...Show more |