Cross-Site Scripting
39 records47.6%First: 2013. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 82 vulnerability records associated with Download Manager, published between 2013 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2013 | 2 | |
| 2014 | 3 | |
| 2015 | 1 | |
| 2016 | 3 | |
| 2017 | 4 | |
| 2018 | 1 | |
| 2019 | 2 | |
| 2021 | 9 | |
| 2022 | 17 | |
| 2023 | 4 | |
| 2024 | 15 | |
| 2025 | 11 | |
| 2026 | 10 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 2.4% |
| High | 18 | 22% |
| Medium | 62 | 75.6% |
First: 2013. Latest: 2026.
First: 2014. Latest: 2026.
First: 2017. Latest: 2025.
First: 2014. Latest: 2025.
First: 2016. Latest: 2026.
First: 2016. Latest: 2026.
First: 2022. Latest: 2025.
First: 2021. Latest: 2021.
First: 2022. Latest: 2024.
First: 2022. Latest: 2022.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.3.673.3.623.3.613.3.523.3.533.3.503.3.473.3.543.3.413.3.313.3.333.3.253.3.263.3.243.3.193.3.133.3.093.3.073.3.043.3.033.3.003.2.993.2.983.2.903.2.943.2.873.2.913.2.853.2.863.2.833.2.716.3.03.2.623.2.603.2.553.2.503.2.543.2.493.2.513.2.443.2.473.2.433.2.393.2.353.2.343.2.223.2.163.2.133.1.253.1.19Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.2.99 | Download Manager <= 3.2.99 - Authenticated (Contributor+) Stored Cross-Site Scripting | October 9, 2024 | 3.3.00 | Medium |
*-3.2.98 | Download Manager <= 3.2.98 - Authenticated (Admin+) Stored Cross-Site Scripting | September 23, 2024 | 3.2.99 | Medium |
*-3.2.97 | Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | July 30, 2024 | 3.2.98 | Medium |
*-3.2.89 | Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary | June 12, 2024 | 3.2.90 | High |
*-3.2.92 | Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes | June 11, 2024 | 3.2.94 | Medium |
*-3.2.86 | Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting | June 11, 2024 | 3.2.87 | Medium |
*-3.2.93 | Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode | June 4, 2024 | 3.2.94 | Medium |
*-3.2.90 | Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode | May 30, 2024 | 3.2.91 | Medium |
*-3.2.84 | Download Manager <= 3.2.84 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 16, 2024 | 3.2.85 | Medium |
*-3.2.84 | Download Manager <= 3.2.84 - Missing Authorization | February 28, 2024 | 3.2.85 | Medium |
*-3.2.85 | Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | February 28, 2024 | 3.2.86 | Medium |
*-3.2.82 | Download Manager <= 3.2.82 - Unauthenticated Password Leak | November 29, 2023 | 3.2.83 | Medium |
*-3.2.70 | Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | May 12, 2023 | 3.2.71 | Medium |
*-3.2.70 | Download Manager <= 3.2.70 - Insufficient Authorization to Information Disclosure | May 8, 2023 | 3.2.71 | Medium |
[4.0, 6.3.0) | Download Manager Pro <= 6.2.9 - Unauthenticated Information Disclosure | April 10, 2023 | 6.3.0 | Medium |
*-3.2.61 | Download Manager <= 3.2.61 - Authenticated (Contributor+) Stored Cross-Site Scripting | December 20, 2022 | 3.2.62 | Medium |
*-3.2.59 | Download Manager <= 3.2.59 - Refleced Cross-Site Scripting | November 29, 2022 | 3.2.60 | Medium |
[*, 3.2.55) | Download Manager <= 3.2.54 - Authenticated (Admin+) Path Traversal | September 5, 2022 | 3.2.55 | Medium |
*-3.2.49 | Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization | August 17, 2022 | 3.2.50 | High |
*-3.2.53 | Download Manager <= 3.2.53 - Reflected Cross-Site Scripting | August 4, 2022 | 3.2.54 | Medium |
*-3.2.48 | Download Manager <= 3.2.48 - Cross-Site Request Forgery | August 2, 2022 | 3.2.49 | High |
*-3.2.48 | Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings Update | August 2, 2022 | 3.2.49 | High |
*-3.2.49 | Download Manager <= 3.2.49 - IP Blocking Bypass | August 1, 2022 | 3.2.50 | Medium |
*-3.2.50 | Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletion | July 27, 2022 | 3.2.51 | High |
*-3.2.48 | Download Manager <= 3.2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting | July 6, 2022 | 3.2.49 | Medium |
Selected source records
Published: July 31, 2026
Published: July 8, 2026
Published: June 30, 2026
Published: April 9, 2026
Published: April 8, 2026
Published: March 18, 2026
Published: February 19, 2026
Published: February 17, 2026
Published: December 15, 2014
Published: January 19, 2016
Published: April 18, 2025
Published: August 2, 2022
Published: August 2, 2022
Published: August 17, 2022
Published: April 30, 2021
Published: April 30, 2021
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.