Download Manager
83 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Download Manager, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Download Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 4 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 2 |
| 2025-04 | 2 |
| 2025-05 | 1 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 3 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 2 |
| 2026-01 | 1 |
| 2026-02 | 1 |
| 2026-03 | 1 |
| 2026-04 | 4 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 1 |
| 2026-09 | 1 |
Severity
How the 83 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High18
- Medium59
Latest CVEs
The 15 most recently published vulnerabilities affecting Download Manager.
- CVE-2026-92714Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter6.5
- CVE-2026-16685Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute6.4
- CVE-2026-14343Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes6.4
- CVE-2026-13733Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute6.4
- CVE-2026-4057Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal4.3
- CVE-2026-5357Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes6.4
- CVE-2026-39676WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability5.3
- CVE-2026-39615WordPress Download Manager plugin <= 3.3.53 - Cross Site Scripting (XSS) vulnerability5.9
- CVE-2026-2571Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter4.3
- CVE-2026-1666Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter6.1
- CVE-2025-15364Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword7.3
- CVE-2025-13498Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure4.3
- CVE-2025-63070WordPress Download Manager plugin <= 3.3.32 - Sensitive Data Exposure vulnerability4.3
- CVE-2025-12177Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key5.3
- CVE-2025-60093WordPress Download Manager Plugin <= 3.3.24 - Cross Site Request Forgery (CSRF) Vulnerability4.3
Product grouping is registry-driven, with AI assist and human review. How it works