CVE Tools

Download Manager

83 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Download Manager, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Download Manager CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Download Manager CVEs per month
MonthCVEs
2024-101
2024-110
2024-124
2025-010
2025-020
2025-032
2025-042
2025-051
2025-061
2025-070
2025-080
2025-093
2025-100
2025-111
2025-122
2026-011
2026-021
2026-031
2026-044
2026-050
2026-060
2026-072
2026-081
2026-091

Severity

How the 83 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical67%
  • High1822%
  • Medium5971%

Latest CVEs

The 15 most recently published vulnerabilities affecting Download Manager.

  1. CVE-2026-92714Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter6.5
  2. CVE-2026-16685Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute6.4
  3. CVE-2026-14343Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes6.4
  4. CVE-2026-13733Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute6.4
  5. CVE-2026-4057Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal4.3
  6. CVE-2026-5357Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes6.4
  7. CVE-2026-39676WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability5.3
  8. CVE-2026-39615WordPress Download Manager plugin <= 3.3.53 - Cross Site Scripting (XSS) vulnerability5.9
  9. CVE-2026-2571Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter4.3
  10. CVE-2026-1666Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter6.1
  11. CVE-2025-15364Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword7.3
  12. CVE-2025-13498Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure4.3
  13. CVE-2025-63070WordPress Download Manager plugin <= 3.3.32 - Sensitive Data Exposure vulnerability4.3
  14. CVE-2025-12177Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key5.3
  15. CVE-2025-60093WordPress Download Manager Plugin <= 3.3.24 - Cross Site Request Forgery (CSRF) Vulnerability4.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store