Eklenti güvenlik geçmişi
Download Manager güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Download Manager eklentisi için 65 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 18 tanesi kritik veya yüksek önemde, 26 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 3.3.72.
- Toplam kayıt
- 65
- Kritik veya yüksek
- 18
- Oturumsuz istismar
- 26
- Son kayıt
- 2 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 3.3.71 ve öncesi · Oturum açmadan istismar edilebilir
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.70 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.71 öncesi
3.3.71 sürümünden önceki Download Manager WordPress eklentisi, bir paket ayarını sayfada görüntülemeden önce yeterince temizlememekte ve kaçış karakterleri eklememektedir; bu durum, “Yazar” rolüne sahip ve daha üst düzey rollere sahip kullanıcıların, paketin indirme penceresini açan herhangi bir ziyaretçiye (yöneticiler dahil) karşı Depolanmış Siteler Arası Komut Dosyası (XSS) saldırıları gerçekleştirmesine olanak tanıyabilir. Ayarın kaydedilmesi sırasında uygulanan temizleme işlemi tek tırnak işaretlerini etkisiz hale getirmediğinden, yalnızca PHP 8.1'den önceki sürümleri çalıştıran siteler bu durumdan etkilenmektedir.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 7.5.6 öncesi · Oturum açmadan istismar edilebilir
7.5.6 sürümünden önceki Download Manager WordPress eklentisi, e-posta ile kilitli indirme abonelik formu aracılığıyla gönderilen verileri, bunları bir yönetici sayfasında görüntülemeden önce temizlememekte ve kaçış karakterleriyle işlememektedir; bu durum, kimlik doğrulaması yapılmamış saldırganların yöneticilere karşı Depolanmış Çapraz Site Komut Dosyası (Stored Cross-Site Scripting) saldırıları gerçekleştirmesine olanak tanıyabilir. Bu sorun yalnızca ticari Pro sürümünü etkilemektedir; aynı slug altında yayınlanan 7.5.6 sürümünden önceki ücretsiz Download Manager WordPress eklentisi, söz konusu özelliği içermemektedir.
Türkçe kayıt ve ne yapmalıyetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 3.3.68 ve öncesi
WordPress için geliştirilen “Download Manager” eklentisi, 3.3.68 sürümüne kadar (bu sürüm dahil) “admin_init” işlevine bağlanan “duplicate()” işlevi aracılığıyla “Güvenli Olmayan Doğrudan Nesne Referansı” güvenlik açığına maruz kalmaktadır. Bunun nedeni, işleyicinin yalnızca genel 'edit_posts' yetkisini ve eklenti genelinde geçerli statik bir nonce (NONCE_KEY) değerini doğrulaması, ancak hedeflenen wpdmpro paket kimliğine karşı herhangi bir nesne düzeyinde yetkilendirme kontrolü yapmamasıdır. Bu durum, Yazar düzeyinde ve üzeri erişim hakkına sahip, kimliği doğrulanmış saldırganların, diğer kullanıcıların (yöneticiler dahil) sahip olduğu herhangi bir Download Manager paketini kopyalamasına olanak tanır; bu işlem, korunan dosya referansları, rol tabanlı erişim kısıtlamaları ve şifre kilidi ayarları dahil olmak üzere tüm paket meta verilerini, saldırganın sahip olduğu bir klona kopyalar; saldırganlar daha sonra bu klonu düzenleyerek kısıtlamaları kaldırabilir ve önceden korunan dosyaları indirebilir.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.66 ve öncesi
WordPress için geliştirilen “Download Manager” eklentisi, yetersiz girdi temizleme ve çıktı kaçış işlemleri nedeniyle 3.3.66 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde “icon” kısa kod özniteliği yoluyla depolanmış siteler arası komut dosyası (Stored Cross-Site Scripting) saldırılarına karşı savunmasızdır. Bu durum, katkıcı düzeyinde veya daha yüksek erişim hakkına sahip, kimliği doğrulanmış saldırganların, bir kullanıcı enjekte edilmiş sayfaya her eriştiğinde çalışacak şekilde sayfalara rastgele web komut dosyaları enjekte etmesine olanak tanır. wp_kses_post() işlevi, yükü etkisiz hale getirmez; çünkü bu işlev, kaydetme anında yazı içeriği üzerinde çalışır ve görüntüleme anında kaçış karakterleri eklenmemiş olarak gönderilen kısa kod öznitelik değerlerini işlemez.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.66 öncesi
3.3.66 sürümünden önceki Download Manager WordPress eklentisi, bir paketin başlığını ön uç paket şablonlarında görüntülemeden önce düzgün bir şekilde kaçış karakterleriyle kodlamamaktadır. Bu durum, “Yazar” rolüne sahip veya daha üst düzey rollere sahip kullanıcıların, paketi gösteren bir sayfayı görüntüleyen herhangi bir kullanıcının (kimliği doğrulanmamış ziyaretçiler dahil) tarayıcısında keyfi JavaScript kodlarının çalıştırılmasına yol açan bir başlık kaydetmesine olanak tanımaktadır.
eksik yetki denetimi
Etkilenen sürümler: 3.3.62 öncesi · Oturum açmadan istismar edilebilir
3.3.62 sürümünden önceki Download Manager WordPress eklentisi, geçici indirme jetonunu istek yapan oturuma bağlamamakta ve jetonun süresini derhal sona erdirmemektedir. Bu durum, jetonu uzun ömürlü, çok kullanımlık ve taşınabilir bir taşıyıcı jeton haline getirmektedir; dolayısıyla, sızdırılmış bir indirme anahtarı ele geçiren bir saldırgan, yetkisiz olarak rol veya parola korumalı paket dosyasını tekrar tekrar indirebilmektedir.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.61 ve öncesi
WordPress için geliştirilen “Download Manager” eklentisi, yetersiz girdi temizleme ve çıktı kaçış işlemleri nedeniyle 3.3.61 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde “note_before” ve “note_after” kısa kod öznitelikleri yoluyla depolanmış siteler arası komut dosyası saldırısına (Stored Cross-Site Scripting) karşı savunmasızdır. Bu durum, katkıcı düzeyinde veya daha yüksek erişim iznine sahip kimliği doğrulanmış saldırganların, bir kullanıcı enjekte edilmiş sayfaya her eriştiğinde çalışacak şekilde sayfalara keyfi web komut dosyaları enjekte etmesine olanak tanır. wp_kses_post, unfiltered_html ayarı olmayan kullanıcılar için kaydetme sırasında yazı içeriğini filtrelediğinden, yalnızca kaydetme sırasındaki filtrelemeyi geçen kses-allowed etiket ve öznitelik yükleri kaçış işleminden geçmemiş alıcıya ulaşır; ancak alıcının kendisi güvenli değildir ve kullanıcı kısa kodu görüntülediğinde bu tür yükler tarayıcıda yine de çalıştırılabilir.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.60 ve öncesi
WordPress için geliştirilen “Download Manager” eklentisi, yetersiz giriş temizleme ve çıktı kaçış işlemlerinden kaynaklanan bir güvenlik açığı nedeniyle, 3.3.60 sürümü dahil olmak üzere tüm sürümlerinde “no_data_msg” kısa kod özniteliği yoluyla depolanmış siteler arası komut enjeksiyonuna (Stored Cross-Site Scripting) karşı savunmasızdır. Bu durum, katkıcı düzeyinde veya daha yüksek erişim hakkına sahip, kimlik doğrulaması yapılmış saldırganların, bir kullanıcı enjekte edilmiş sayfaya her eriştiğinde çalıştırılacak şekilde sayfalara rastgele web komut dosyaları enjekte etmesine olanak tanır. wp_kses_post, kaydetme sırasında yazı içeriğine uygulanmasına rağmen, yalnızca HTML belirteçlerini kaldırır ve kısa kod öznitelik değerlerine gömülü C tarzı kaçış dizilerini etkisiz hale getirmez; bu da, katkıcıların kses filtresinden geçebilen ve görüntüleme sırasında sessizce ham bir script etiketine dönüştürülen bir yük oluşturabilecekleri anlamına gelir.
eksik yetki denetimi
Etkilenen sürümler: 3.3.51 ve öncesi
WordPress için geliştirilen “Download Manager” eklentisi, 3.3.51 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde `makeMediaPublic()` ve `makeMediaPrivate()` işlevlerinde yetki kontrolünün eksik olması nedeniyle, verilerin yetkisiz olarak değiştirilmesine karşı savunmasızdır. Bunun nedeni, işlevlerin yalnızca `edit_posts` yetkisini kontrol etmesi ve `current_user_can('edit_post', $id)` yoluyla yazı sahipliğini doğrulamaması ve `mediaAccessControl()` içindeki yönetici düzeyindeki kontrol işleminden önce yıkıcı işlemlerin yürütülmesidir. Bu durum, Contributor düzeyinde veya daha yüksek erişim iznine sahip kimliği doğrulanmış saldırganların, kendilerine ait olmayan herhangi bir medya dosyasından tüm koruma meta verilerini (şifre, erişim kısıtlamaları, özel bayrağı) kaldırmasına ve böylece yönetici tarafından korunan dosyalara doğrudan URL yoluyla herkesin erişebilmesini mümkün kılar.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.52 ve öncesi
WordPress için geliştirilen Download Manager eklentisi, 3.3.52 sürümüne kadar (bu sürüm dahil) 'wpdm_members' kısa kodunun 'sid' parametresi yoluyla Saklı Çapraz Site Komut Yürütme (Stored Cross-Site Scripting) saldırısına açıktır. Bu durum, kullanıcı tarafından sağlanan 'sid' kısa kod özniteliğinde giriş temizleme ve çıkış kaçış işlemlerinin yetersiz olmasından kaynaklanmaktadır. sid parametresi, members() işlevinde temizleme yapılmadan çıkarılır ve update_post_meta() aracılığıyla depolanır; ardından esc_attr() uygulanmadan doğrudan members.php şablonundaki bir HTML id özniteliğine eklenir. Bu durum, katkıcı düzeyinde veya daha üst düzey erişim hakkına sahip, kimlik doğrulaması yapılmış saldırganların, bir kullanıcı enjekte edilen sayfaya her eriştiğinde çalışacak şekilde sayfalara keyfi web komut dosyaları enjekte etmesine olanak tanır.
eksik yetki denetimi
Etkilenen sürümler: 3.3.52 ve öncesi · Oturum açmadan istismar edilebilir
Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through'de <= 3.3.52 sürümlerinde yetki eksikliği güvenlik açığı.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.53 ve öncesi
Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through <= 3.3.53 sürümlerinde, web sayfası oluşturma sırasında girdilerin uygun şekilde nötralize edilmemesi nedeniyle ortaya çıkan ‘Siteler Arası Komut Dosyası Yürütme’ güvenlik açığı.
hassas bilgi ifşası
Etkilenen sürümler: 3.3.49 ve öncesi
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email addresses, display names, and registration dates.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.46 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient input sanitization and output escaping on the 'redirect_to' GET parameter in the login form shortcode. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
yetki yükseltme
Etkilenen sürümler: 3.3.40 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account.
eksik yetki denetimi
Etkilenen sürümler: 3.3.32 ve öncesi
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.
hassas bilgi ifşası
Etkilenen sürümler: 3.3.32 ve öncesi
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32.
güvenlik
Etkilenen sürümler: 3.3.30 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of expired posts and clearing cache.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.3.24 ve öncesi · Oturum açmadan istismar edilebilir
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request Forgery.This issue affects Download Manager: from n/a through <= 3.3.24.
hassas bilgi ifşası
Etkilenen sürümler: 3.3.25 ve öncesi · Oturum açmadan istismar edilebilir
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.25.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.23 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.18 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.99 öncesi
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
rastgele dosya silme
Etkilenen sürümler: 3.3.12 ve öncesi
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all versions up to, and including, 3.3.12. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.12 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
hassas bilgi ifşası
Etkilenen sürümler: 3.3.07 öncesi
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
dizin geçişi (path traversal)
Etkilenen sürümler: 3.3.08 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.
eksik yetki denetimi
Etkilenen sürümler: 3.3.03 ve öncesi
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.03.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.03 öncesi
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
eksik yetki denetimi
Etkilenen sürümler: 3.3.03 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
uzaktan kod çalıştırma
Etkilenen sürümler: 3.3.03 ve öncesi · Oturum açmadan istismar edilebilir
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.00 öncesi
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.97 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
güvenlik
Etkilenen sürümler: 3.2.89 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.86 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.92 ve öncesi
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.93 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.90 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
hassas bilgi ifşası
Etkilenen sürümler: 3.2.82 ve öncesi · Oturum açmadan istismar edilebilir
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.84 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.85 ve öncesi
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
eksik yetki denetimi
Etkilenen sürümler: 3.2.84 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
güvenlik
Etkilenen sürümler: 3.2.83 öncesi · Oturum açmadan istismar edilebilir
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.70 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
güvenlik
Etkilenen sürümler: 3.2.71 öncesi
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.
güvenlik
Etkilenen sürümler: 6.3.0 öncesi · Oturum açmadan istismar edilebilir
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.62 öncesi
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
dizin geçişi (path traversal)
Etkilenen sürümler: 3.2.55 öncesi
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
PHP nesne enjeksiyonu
Etkilenen sürümler: 3.2.49 ve öncesi
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
rastgele dosya silme
Etkilenen sürümler: 3.2.50 ve öncesi
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the /wp-config.php file which will reset the installation and make it possible for an attacker to achieve remote code execution on the server.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.2.48 ve öncesi · Oturum açmadan istismar edilebilir
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.48 ve öncesi
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.2.48 ve öncesi · Oturum açmadan istismar edilebilir
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.50 öncesi · Oturum açmadan istismar edilebilir
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.46 ve öncesi
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.44 öncesi · Oturum açmadan istismar edilebilir
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.42 ve öncesi · Oturum açmadan istismar edilebilir
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
güvenlik
Etkilenen sürümler: 3.2.34 öncesi · Oturum açmadan istismar edilebilir
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
eksik yetki denetimi
Etkilenen sürümler: 3.2.35 öncesi · Oturum açmadan istismar edilebilir
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
SQL enjeksiyonu
Etkilenen sürümler: 3.2.34 öncesi
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
açık yönlendirme
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2013-73196 Şubat 2014
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.5.9 öncesi
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Türkçe açıklamalar makine çevirisidir; bağlayıcı metin NVD’deki İngilizce kayıttır. Veri 7 Ekim 2026 itibarıyla.