Wpdownloadmanager is a narrowly scoped WordPress plugin ecosystem focused on digital product delivery and download management, with vulnerability exposure centered on its premium packages and Gutenberg integration components. The observed weakness classes reflect the plugin's web-facing and administrative scope, clustering around input validation, cross-site scripting, SQL injection, and privilege management issues typical of WordPress extensions that handle commerce and access control. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdownloadmanager over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52435HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM | Nov 18, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-4001MEDIUM The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2. | Jun 5, 2024 | 5.4 | 20 | NO | NO |
CVE-2023-4293MEDIUM The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restric | Aug 12, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-22713MEDIUM Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions. | May 3, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-7386MEDIUM The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to m | Sep 25, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdownloadmanager.
Media articles that mention a CVE ID that affects a product developed by Wpdownloadmanager — matched by CVE ID, not by vendor name.