Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Download Manager Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 82 vulnerability records associated with Download Manager, published between 2013 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

82Total records
2Critical
18High
62Medium
0Low
0Informational
82Patched records
0Currently marked unpatched
2013-12-07First disclosure
2026-07-31Latest disclosure
65 of 82CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201322 records
201433 records
201511 records
201633 records
201744 records
201811 records
201922 records
202199 records
20221717 records
202344 records
20241515 records
20251111 records
20261010 records

Severity Breakdown

SeverityRecordsShare
Critical22.4%
High1822%
Medium6275.6%

Vulnerability-Type Breakdown

Cross-Site Scripting

39 records47.6%

First: 2013. Latest: 2026.

Missing Authorization

11 records13.4%

First: 2014. Latest: 2026.

CSRF

7 records8.5%

First: 2017. Latest: 2025.

Other

6 records7.3%

First: 2014. Latest: 2025.

Information Disclosure

6 records7.3%

First: 2016. Latest: 2026.

Privilege Escalation

4 records4.9%

First: 2016. Latest: 2026.

Path Traversal

4 records4.9%

First: 2022. Latest: 2025.

Arbitrary File Upload

2 records2.4%

First: 2021. Latest: 2021.

Authentication Bypass

2 records2.4%

First: 2022. Latest: 2024.

SQL Injection

1 record1.2%

First: 2022. Latest: 2022.

Patch Status

Patched
82
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.3.67
  • 3.3.62
  • 3.3.61
  • 3.3.52
  • 3.3.53
  • 3.3.50
  • 3.3.47
  • 3.3.54
  • 3.3.41
  • 3.3.31
  • 3.3.33
  • 3.3.25
  • 3.3.26
  • 3.3.24
  • 3.3.19
  • 3.3.13
  • 3.3.09
  • 3.3.07
  • 3.3.04
  • 3.3.03
  • 3.3.00
  • 3.2.99
  • 3.2.98
  • 3.2.90
  • 3.2.94
  • 3.2.87
  • 3.2.91
  • 3.2.85
  • 3.2.86
  • 3.2.83
  • 3.2.71
  • 6.3.0
  • 3.2.62
  • 3.2.60
  • 3.2.55
  • 3.2.50
  • 3.2.54
  • 3.2.49
  • 3.2.51
  • 3.2.44
  • 3.2.47
  • 3.2.43
  • 3.2.39
  • 3.2.35
  • 3.2.34
  • 3.2.22
  • 3.2.16
  • 3.2.13
  • 3.1.25
  • 3.1.19

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.2.99Download Manager <= 3.2.99 - Authenticated (Contributor+) Stored Cross-Site ScriptingOctober 9, 20243.3.00Medium
*-3.2.98Download Manager <= 3.2.98 - Authenticated (Admin+) Stored Cross-Site ScriptingSeptember 23, 20243.2.99Medium
*-3.2.97Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeJuly 30, 20243.2.98Medium
*-3.2.89Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibraryJune 12, 20243.2.90High
*-3.2.92Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple ShortcodesJune 11, 20243.2.94Medium
*-3.2.86Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site ScriptingJune 11, 20243.2.87Medium
*-3.2.93Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form ShortcodeJune 4, 20243.2.94Medium
*-3.2.90Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages ShortcodeMay 30, 20243.2.91Medium
*-3.2.84Download Manager <= 3.2.84 - Authenticated (Contributor+) Stored Cross-Site ScriptingMarch 16, 20243.2.85Medium
*-3.2.84Download Manager <= 3.2.84 - Missing AuthorizationFebruary 28, 20243.2.85Medium
*-3.2.85Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeFebruary 28, 20243.2.86Medium
*-3.2.82Download Manager <= 3.2.82 - Unauthenticated Password LeakNovember 29, 20233.2.83Medium
*-3.2.70Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeMay 12, 20233.2.71Medium
*-3.2.70Download Manager <= 3.2.70 - Insufficient Authorization to Information DisclosureMay 8, 20233.2.71Medium
[4.0, 6.3.0)Download Manager Pro <= 6.2.9 - Unauthenticated Information DisclosureApril 10, 20236.3.0Medium
*-3.2.61Download Manager <= 3.2.61 - Authenticated (Contributor+) Stored Cross-Site ScriptingDecember 20, 20223.2.62Medium
*-3.2.59Download Manager <= 3.2.59 - Refleced Cross-Site ScriptingNovember 29, 20223.2.60Medium
[*, 3.2.55)Download Manager <= 3.2.54 - Authenticated (Admin+) Path TraversalSeptember 5, 20223.2.55Medium
*-3.2.49Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR DeserializationAugust 17, 20223.2.50High
*-3.2.53Download Manager <= 3.2.53 - Reflected Cross-Site ScriptingAugust 4, 20223.2.54Medium
*-3.2.48Download Manager <= 3.2.48 - Cross-Site Request ForgeryAugust 2, 20223.2.49High
*-3.2.48Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings UpdateAugust 2, 20223.2.49High
*-3.2.49Download Manager <= 3.2.49 - IP Blocking BypassAugust 1, 20223.2.50Medium
*-3.2.50Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File DeletionJuly 27, 20223.2.51High
*-3.2.48Download Manager <= 3.2.48 - Authenticated (Contributor+) Stored Cross-Site ScriptingJuly 6, 20223.2.49Medium

Selected source records

Latest Records

MediumCVE-2026-16685

Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute

Published: July 31, 2026

Affected versions
*-3.3.66
Patched versions
3.3.67
Original Wordfence record
MediumCVE-2026-14343

Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes

Published: July 8, 2026

Affected versions
*-3.3.61
Patched versions
3.3.62
Original Wordfence record
MediumCVE-2026-13733

Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute

Published: June 30, 2026

Affected versions
*-3.3.60
Patched versions
3.3.61
Original Wordfence record
MediumCVE-2026-4057

Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal

Published: April 9, 2026

Affected versions
*-3.3.51
Patched versions
3.3.52
Original Wordfence record
MediumCVE-2026-5357

Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Published: April 8, 2026

Affected versions
*-3.3.52
Patched versions
3.3.53
Original Wordfence record
MediumCVE-2026-2571

Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter

Published: March 18, 2026

Affected versions
*-3.3.49
Patched versions
3.3.50
Original Wordfence record
MediumCVE-2026-39676

Download Manager <= 3.3.52 - Missing Authorization

Published: February 19, 2026

Affected versions
*-3.3.52
Patched versions
3.3.53
Original Wordfence record
MediumCVE-2026-1666

Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter

Published: February 17, 2026

Affected versions
*-3.3.46
Patched versions
3.3.47
Original Wordfence record

Highest-Severity Records

Critical

WordPress Download Manager <= 2.7.4 - Remote Code Execution

Published: December 15, 2014

Affected versions
[*, 2.7.5)
Patched versions
2.7.5
Original Wordfence record
Critical

Download Manager <= 2.8.7 - Missing Authorization

Published: January 19, 2016

Affected versions
[*, 2.8.8)
Patched versions
2.8.8
Original Wordfence record
HighCVE-2025-3404

Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion

Published: April 18, 2025

Affected versions
*-3.3.12
Patched versions
3.3.13
Original Wordfence record
HighCVE-2022-34347

Download Manager <= 3.2.48 - Cross-Site Request Forgery to Plugin Settings Update

Published: August 2, 2022

Affected versions
*-3.2.48
Patched versions
3.2.49
Original Wordfence record
HighCVE-2022-36288

Download Manager <= 3.2.48 - Cross-Site Request Forgery

Published: August 2, 2022

Affected versions
*-3.2.48
Patched versions
3.2.49
Original Wordfence record
HighCVE-2022-2436

Download Manager <= 3.2.49 - Authenticated (Contributor+) PHAR Deserialization

Published: August 17, 2022

Affected versions
*-3.2.49
Patched versions
3.2.50
Original Wordfence record
High

WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery

Published: April 30, 2021

Affected versions
[*, 3.1.22)
Patched versions
3.1.22
Original Wordfence record
High

WordPress Download Manager < 3.1.19 - Arbitrary File Upload

Published: April 30, 2021

Affected versions
[*, 3.1.19)
Patched versions
3.1.19
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory