W3eden develops a narrow portfolio of WordPress plugins and web-based productivity components, including a download manager, form-builder, and pricing-table tool, that collectively reach a moderate volume of disclosures despite their focused scope. The vendor's vulnerability profile centers on web-application input handling and authorization weaknesses—cross-site scripting, cross-site request forgery, missing authorization checks, and path-traversal issues—that are characteristic of server-side WordPress extensions and reflect the challenges of secure form handling and file access control in plugin environments. Public exploit code tends to be available for vulnerabilities affecting this vendor, reflecting the transparency of WordPress plugin codebases and the attentiveness of the security research community to widely installed extensions. Defenders should prioritize patches for internet-exposed WordPress installations running these plugins and monitor the vendor's release cycles for authorization and input-validation fixes. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by W3eden over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15889MEDIUM The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter. | Sep 3, 2019 | 6.1 | 45 | NO | YES |
CVE-2014-9260HIGH The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option. | Aug 7, 2017 | 8.8 | 36 | NO | YES |
CVE-2024-11740HIGH The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing user | Dec 19, 2024 | 7.3 | 32 | NO | YES |
CVE-2023-6421HIGH The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. | Jan 1, 2024 | 7.5 | 32 | NO | YES |
CVE-2022-2168MEDIUM The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-S | Jul 17, 2022 | 6.1 | 32 | NO | YES |
CVE-2022-45836MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions. | Apr 18, 2023 | 6.1 | 31 | NO | YES |
CVE-2022-2431HIGH The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validatio | Sep 6, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-36288HIGH Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. | Aug 23, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-25069HIGH The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can | Feb 21, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-34639HIGH Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is exec | Aug 5, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by W3eden.
Media articles that mention a CVE ID that affects a product developed by W3eden — matched by CVE ID, not by vendor name.