Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

W3eden

First CVE: Feb 6, 2014Active for: 12 yearsTotal CVEs: 51
34.4
VTI Score
Medium

W3eden develops a narrow portfolio of WordPress plugins and web-based productivity components, including a download manager, form-builder, and pricing-table tool, that collectively reach a moderate volume of disclosures despite their focused scope. The vendor's vulnerability profile centers on web-application input handling and authorization weaknesses—cross-site scripting, cross-site request forgery, missing authorization checks, and path-traversal issues—that are characteristic of server-side WordPress extensions and reflect the challenges of secure form handling and file access control in plugin environments. Public exploit code tends to be available for vulnerabilities affecting this vendor, reflecting the transparency of WordPress plugin codebases and the attentiveness of the security research community to widely installed extensions. Defenders should prioritize patches for internet-exposed WordPress installations running these plugins and monitor the vendor's release cycles for authorization and input-validation fixes. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
51
Total CVEs
More Total CVEs than 98% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by W3eden over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2014
12 years ago
Most Recent CVE
Jun 19, 2025
400 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (51 CVEs).

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15889MEDIUM
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
Sep 3, 20196.145NOYES
CVE-2014-9260HIGH
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
Aug 7, 20178.836NOYES
CVE-2024-11740HIGH
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing user
Dec 19, 20247.332NOYES
CVE-2023-6421HIGH
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
Jan 1, 20247.532NOYES
CVE-2022-2168MEDIUM
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-S
Jul 17, 20226.132NOYES
CVE-2022-45836MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
Apr 18, 20236.131NOYES
CVE-2022-2431HIGH
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validatio
Sep 6, 20228.829NONO
CVE-2022-36288HIGH
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Aug 23, 20228.828NONO
CVE-2021-25069HIGH
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can
Feb 21, 20228.827NONO
CVE-2021-34639HIGH
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is exec
Aug 5, 20218.827NONO
View all 51 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products51 CVEs
67%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network49 (96.1%)
Unknown2 (3.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low48 (94.1%)
High1 (2.0%)
Unknown2 (3.9%)
User Interaction
None20 (39.2%)
Unknown2 (3.9%)
Required29 (56.9%)
Privileges Required
Low23 (45.1%)
High4 (7.8%)
None22 (43.1%)
Unknown2 (3.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (51 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
11.8% of CVEs· 96th percentile
ExploitDB
3 CVEs
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by W3eden.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by W3eden — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For W3eden's Products

View all 6 CNAs →

Top CWEs