CVE-2023-1524
- EPSS 0.18%
- Veröffentlicht 30.05.2023 08:15:09
- Zuletzt bearbeitet 21.03.2025 19:19:25
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on ...
CVE-2023-1809
- EPSS 0.23%
- Veröffentlicht 02.05.2023 08:15:10
- Zuletzt bearbeitet 21.03.2025 16:23:20
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
CVE-2022-45836
- EPSS 0.13%
- Veröffentlicht 18.04.2023 14:15:07
- Zuletzt bearbeitet 21.03.2025 19:19:36
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
CVE-2022-4476
- EPSS 0.25%
- Veröffentlicht 16.01.2023 16:15:12
- Zuletzt bearbeitet 04.04.2025 18:15:44
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scrip...
CVE-2022-2436
- EPSS 1.13%
- Veröffentlicht 06.09.2022 18:15:13
- Zuletzt bearbeitet 05.05.2025 17:18:09
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privilege...
CVE-2022-2431
- EPSS 17.14%
- Veröffentlicht 06.09.2022 18:15:13
- Zuletzt bearbeitet 21.03.2025 16:07:09
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php...
CVE-2022-36288
- EPSS 0.1%
- Veröffentlicht 23.08.2022 16:15:11
- Zuletzt bearbeitet 21.03.2025 16:07:09
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
CVE-2022-34658
- EPSS 0.2%
- Veröffentlicht 23.08.2022 16:15:10
- Zuletzt bearbeitet 21.03.2025 16:07:09
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
CVE-2022-34347
- EPSS 0.1%
- Veröffentlicht 22.08.2022 15:15:16
- Zuletzt bearbeitet 21.03.2025 16:07:09
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
CVE-2022-2362
- EPSS 0.51%
- Veröffentlicht 22.08.2022 15:15:14
- Zuletzt bearbeitet 21.03.2025 16:07:09
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.