Show filters
97 Total Results
Displaying 21-30 of 97
Sort by:
Attacker Value
Unknown
CVE-2023-6785
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
0
Attacker Value
Unknown
CVE-2023-6421
Disclosure Date: January 01, 2024 (last updated January 09, 2024)
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
0
Attacker Value
Unknown
CVE-2023-2305
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-1524
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.
0
Attacker Value
Unknown
CVE-2023-22713
Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
0
Attacker Value
Unknown
CVE-2023-1809
Disclosure Date: May 02, 2023 (last updated October 08, 2023)
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
0
Attacker Value
Unknown
CVE-2022-45836
Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
0
Attacker Value
Unknown
CVE-2022-4476
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
0
Attacker Value
Unknown
CVE-2022-3076
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
0
Attacker Value
Unknown
CVE-2022-2926
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
0