Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Download Manager Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 82 vulnerability records associated with Download Manager, published between 2013 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

82Total records
2Critical
18High
62Medium
0Low
0Informational
82Patched records
0Currently marked unpatched
2013-12-07First disclosure
2026-07-31Latest disclosure
65 of 82CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201322 records
201433 records
201511 records
201633 records
201744 records
201811 records
201922 records
202199 records
20221717 records
202344 records
20241515 records
20251111 records
20261010 records

Severity Breakdown

SeverityRecordsShare
Critical22.4%
High1822%
Medium6275.6%

Vulnerability-Type Breakdown

Cross-Site Scripting

39 records47.6%

First: 2013. Latest: 2026.

Missing Authorization

11 records13.4%

First: 2014. Latest: 2026.

CSRF

7 records8.5%

First: 2017. Latest: 2025.

Other

6 records7.3%

First: 2014. Latest: 2025.

Information Disclosure

6 records7.3%

First: 2016. Latest: 2026.

Privilege Escalation

4 records4.9%

First: 2016. Latest: 2026.

Path Traversal

4 records4.9%

First: 2022. Latest: 2025.

Arbitrary File Upload

2 records2.4%

First: 2021. Latest: 2021.

Authentication Bypass

2 records2.4%

First: 2022. Latest: 2024.

SQL Injection

1 record1.2%

First: 2022. Latest: 2022.

Patch Status

Patched
82
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.3.67
  • 3.3.62
  • 3.3.61
  • 3.3.52
  • 3.3.53
  • 3.3.50
  • 3.3.47
  • 3.3.54
  • 3.3.41
  • 3.3.31
  • 3.3.33
  • 3.3.25
  • 3.3.26
  • 3.3.24
  • 3.3.19
  • 3.3.13
  • 3.3.09
  • 3.3.07
  • 3.3.04
  • 3.3.03
  • 3.3.00
  • 3.2.99
  • 3.2.98
  • 3.2.90
  • 3.2.94
  • 3.2.87
  • 3.2.91
  • 3.2.85
  • 3.2.86
  • 3.2.83
  • 3.2.71
  • 6.3.0
  • 3.2.62
  • 3.2.60
  • 3.2.55
  • 3.2.50
  • 3.2.54
  • 3.2.49
  • 3.2.51
  • 3.2.44
  • 3.2.47
  • 3.2.43
  • 3.2.39
  • 3.2.35
  • 3.2.34
  • 3.2.22
  • 3.2.16
  • 3.2.13
  • 3.1.25
  • 3.1.19

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.3.66Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode AttributeJuly 31, 20263.3.67Medium
*-3.3.61Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode AttributesJuly 8, 20263.3.62Medium
*-3.3.60Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode AttributeJune 30, 20263.3.61Medium
*-3.3.51Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection RemovalApril 9, 20263.3.52Medium
*-3.3.52Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesApril 8, 20263.3.53Medium
*-3.3.49Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' ParameterMarch 18, 20263.3.50Medium
*-3.3.52Download Manager <= 3.3.52 - Missing AuthorizationFebruary 19, 20263.3.53Medium
*-3.3.46Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' ParameterFebruary 17, 20263.3.47Medium
*-3.3.53Download Manager <= 3.3.53 - Authenticated (Author+) Stored Cross-Site ScriptingFebruary 10, 20263.3.54Medium
*-3.3.40Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePasswordJanuary 5, 20263.3.41High
*-3.3.32Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password DisclosureDecember 17, 20253.3.33Medium
*-3.3.30Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron KeyNovember 7, 20253.3.31Medium
*-3.3.32Download Manager <= 3.3.32 - Authenticated (Subscriber+) Information ExposureSeptember 30, 20253.3.33Medium
*-3.3.24Download Manager <= 3.3.24 - Cross-Site Request ForgerySeptember 26, 20253.3.25Medium
*-3.3.25Download Manager <= 3.3.25 - Unauthenticated Sensitive Information ExposureSeptember 26, 20253.3.26Medium
*-3.3.23Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` ParameterSeptember 18, 20253.3.24Medium
*-3.3.18Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard ShortcodeJune 18, 20253.3.19Medium
*-3.3.12Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File DeletionApril 18, 20253.3.13High
*-3.3.12Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadApril 17, 20253.3.13Medium
*-3.3.08Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File OverwriteMarch 12, 20253.3.09Medium
*-3.3.06Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected DirectoryJanuary 17, 20253.3.07Medium
*-3.3.03Download Manager <= 3.3.03 - Missing AuthorizationDecember 19, 20243.3.04Medium
*-3.3.03Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected FilesDecember 18, 20243.3.04Medium
*-3.3.03Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode ExecutionDecember 18, 20243.3.04High
*-3.3.02Download Manager <= 3.3.02 - Authenticated (Admin+) Stored Cross-Site ScriptingNovember 29, 20243.3.03Medium

Selected source records

Latest Records

MediumCVE-2026-16685

Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute

Published: July 31, 2026

Affected versions
*-3.3.66
Patched versions
3.3.67
Original Wordfence record
MediumCVE-2026-14343

Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes

Published: July 8, 2026

Affected versions
*-3.3.61
Patched versions
3.3.62
Original Wordfence record
MediumCVE-2026-13733

Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute

Published: June 30, 2026

Affected versions
*-3.3.60
Patched versions
3.3.61
Original Wordfence record
MediumCVE-2026-4057

Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal

Published: April 9, 2026

Affected versions
*-3.3.51
Patched versions
3.3.52
Original Wordfence record
MediumCVE-2026-5357

Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Published: April 8, 2026

Affected versions
*-3.3.52
Patched versions
3.3.53
Original Wordfence record
MediumCVE-2026-2571

Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter

Published: March 18, 2026

Affected versions
*-3.3.49
Patched versions
3.3.50
Original Wordfence record
MediumCVE-2026-39676

Download Manager <= 3.3.52 - Missing Authorization

Published: February 19, 2026

Affected versions
*-3.3.52
Patched versions
3.3.53
Original Wordfence record
MediumCVE-2026-1666

Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter

Published: February 17, 2026

Affected versions
*-3.3.46
Patched versions
3.3.47
Original Wordfence record

Highest-Severity Records

Critical

WordPress Download Manager <= 2.7.4 - Remote Code Execution

Published: December 15, 2014

Affected versions
[*, 2.7.5)
Patched versions
2.7.5
Original Wordfence record
Critical

Download Manager <= 2.8.7 - Missing Authorization

Published: January 19, 2016

Affected versions
[*, 2.8.8)
Patched versions
2.8.8
Original Wordfence record
HighCVE-2025-3404

Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion

Published: April 18, 2025

Affected versions
*-3.3.12
Patched versions
3.3.13
Original Wordfence record
HighCVE-2022-34347

Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings Update

Published: August 2, 2022

Affected versions
*-3.2.48
Patched versions
3.2.49
Original Wordfence record
HighCVE-2022-36288

Download Manager <= 3.2.48 - Cross-Site Request Forgery

Published: August 2, 2022

Affected versions
*-3.2.48
Patched versions
3.2.49
Original Wordfence record
HighCVE-2022-2436

Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization

Published: August 17, 2022

Affected versions
*-3.2.49
Patched versions
3.2.50
Original Wordfence record
High

WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery

Published: April 30, 2021

Affected versions
[*, 3.1.22)
Patched versions
3.1.22
Original Wordfence record
High

WordPress Download Manager < 3.1.19 - Arbitrary File Upload

Published: April 30, 2021

Affected versions
[*, 3.1.19)
Patched versions
3.1.19
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory