Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.75% | — | Wpdownloadmanager Wp-downloadmanagerAI | 18/2/2026 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass the WP_CONTENT_DIR prefix… | |
| Aplazada | Alta (7.2) | 0.66% | — | Wpdownloadmanager Wp-downloadmanagerAI | 26/9/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on… | |
| Analizada | Alta (7.2) | 0.94% | — | Wp-downloadmanager Project Wp-downloadmanager | 11/6/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary… | |
| Analizada | Media (4.9) | 0.42% | — | Wp-downloadmanager Project Wp-downloadmanager | 11/6/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Aplazada | Alta (7.1) | 0.32% | — | Lesterchan Wp-downloadmanagerAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-DownloadManager wp-downloadmanager allows Reflected XSS.This issue affects WP-DownloadManager: from n/a through <= 1.68.8. | |
| Modificada | Media (5.4) | 0.57% | — | Wp-downloadmanager Project Wp-downloadmanager | 25/3/2022 | 17/6/2026 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories. | |
| Modificada | Media (5.4) | 0.56% | — | Wp-downloadmanager Project Wp-downloadmanager | 18/3/2022 | 17/6/2026 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url. | |
| Modificada | Media (5.4) | 0.54% | — | Wp-downloadmanager Project Wp-downloadmanager | 18/3/2022 | 17/6/2026 | Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions. | |
| Modificada | Media (5.3) | 0.93% | — | Wp-downloadmanager Project Wp-downloadmanager | 7/7/2021 | 17/6/2026 | Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services | |
| Modificada | Media (6.8) | 0.95% | — | Lesterchan Wp-downloadmanager | 19/4/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. |