Cross-Site Scripting
39 records47.6%First: 2013. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 82 vulnerability records associated with Download Manager, published between 2013 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2013 | 2 | |
| 2014 | 3 | |
| 2015 | 1 | |
| 2016 | 3 | |
| 2017 | 4 | |
| 2018 | 1 | |
| 2019 | 2 | |
| 2021 | 9 | |
| 2022 | 17 | |
| 2023 | 4 | |
| 2024 | 15 | |
| 2025 | 11 | |
| 2026 | 10 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 2.4% |
| High | 18 | 22% |
| Medium | 62 | 75.6% |
First: 2013. Latest: 2026.
First: 2014. Latest: 2026.
First: 2017. Latest: 2025.
First: 2014. Latest: 2025.
First: 2016. Latest: 2026.
First: 2016. Latest: 2026.
First: 2022. Latest: 2025.
First: 2021. Latest: 2021.
First: 2022. Latest: 2024.
First: 2022. Latest: 2022.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.3.673.3.623.3.613.3.523.3.533.3.503.3.473.3.543.3.413.3.313.3.333.3.253.3.263.3.243.3.193.3.133.3.093.3.073.3.043.3.033.3.003.2.993.2.983.2.903.2.943.2.873.2.913.2.853.2.863.2.833.2.716.3.03.2.623.2.603.2.553.2.503.2.543.2.493.2.513.2.443.2.473.2.433.2.393.2.353.2.343.2.223.2.163.2.133.1.253.1.19Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.3.66 | Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute | July 31, 2026 | 3.3.67 | Medium |
*-3.3.61 | Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes | July 8, 2026 | 3.3.62 | Medium |
*-3.3.60 | Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute | June 30, 2026 | 3.3.61 | Medium |
*-3.3.51 | Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal | April 9, 2026 | 3.3.52 | Medium |
*-3.3.52 | Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | April 8, 2026 | 3.3.53 | Medium |
*-3.3.49 | Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter | March 18, 2026 | 3.3.50 | Medium |
*-3.3.52 | Download Manager <= 3.3.52 - Missing Authorization | February 19, 2026 | 3.3.53 | Medium |
*-3.3.46 | Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter | February 17, 2026 | 3.3.47 | Medium |
*-3.3.53 | Download Manager <= 3.3.53 - Authenticated (Author+) Stored Cross-Site Scripting | February 10, 2026 | 3.3.54 | Medium |
*-3.3.40 | Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword | January 5, 2026 | 3.3.41 | High |
*-3.3.32 | Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure | December 17, 2025 | 3.3.33 | Medium |
*-3.3.30 | Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key | November 7, 2025 | 3.3.31 | Medium |
*-3.3.32 | Download Manager <= 3.3.32 - Authenticated (Subscriber+) Information Exposure | September 30, 2025 | 3.3.33 | Medium |
*-3.3.24 | Download Manager <= 3.3.24 - Cross-Site Request Forgery | September 26, 2025 | 3.3.25 | Medium |
*-3.3.25 | Download Manager <= 3.3.25 - Unauthenticated Sensitive Information Exposure | September 26, 2025 | 3.3.26 | Medium |
*-3.3.23 | Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter | September 18, 2025 | 3.3.24 | Medium |
*-3.3.18 | Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode | June 18, 2025 | 3.3.19 | Medium |
*-3.3.12 | Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion | April 18, 2025 | 3.3.13 | High |
*-3.3.12 | Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | April 17, 2025 | 3.3.13 | Medium |
*-3.3.08 | Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite | March 12, 2025 | 3.3.09 | Medium |
*-3.3.06 | Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory | January 17, 2025 | 3.3.07 | Medium |
*-3.3.03 | Download Manager <= 3.3.03 - Missing Authorization | December 19, 2024 | 3.3.04 | Medium |
*-3.3.03 | Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files | December 18, 2024 | 3.3.04 | Medium |
*-3.3.03 | Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution | December 18, 2024 | 3.3.04 | High |
*-3.3.02 | Download Manager <= 3.3.02 - Authenticated (Admin+) Stored Cross-Site Scripting | November 29, 2024 | 3.3.03 | Medium |
Selected source records
Published: July 31, 2026
Published: July 8, 2026
Published: June 30, 2026
Published: April 9, 2026
Published: April 8, 2026
Published: March 18, 2026
Published: February 19, 2026
Published: February 17, 2026
Published: December 15, 2014
Published: January 19, 2016
Published: April 18, 2025
Published: August 2, 2022
Published: August 2, 2022
Published: August 17, 2022
Published: April 30, 2021
Published: April 30, 2021
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.