CVE-2021-34638
- EPSS 0.78%
- Veröffentlicht 05.08.2021 21:15:12
- Zuletzt bearbeitet 21.03.2025 16:07:09
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download temp...
CVE-2019-15889
- EPSS 4.27%
- Veröffentlicht 03.09.2019 18:15:12
- Zuletzt bearbeitet 21.03.2025 16:07:09
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
CVE-2017-18032
- EPSS 0.21%
- Veröffentlicht 16.01.2018 09:29:00
- Zuletzt bearbeitet 21.03.2025 16:07:09
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
CVE-2014-9260
- EPSS 3.81%
- Veröffentlicht 07.08.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
CVE-2017-2217
- EPSS 0.36%
- Veröffentlicht 07.07.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2017-2216
- EPSS 0.48%
- Veröffentlicht 07.07.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 0.2%
- Veröffentlicht 04.11.2014 15:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
CVE-2013-7319
- EPSS 4.54%
- Veröffentlicht 06.02.2014 16:10:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.