Pricing
Case studies
Login
Start trial
Download Manager
Shahjada
Developer
3.3.52
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
65 patched
15 Mitigation rules
Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter vulnerability
<= 3.3.49
19/03/2026
Reflected Cross-Site Scripting via 'redirect_to' Parameter vulnerability
<= 3.3.46
18/02/2026
Unauthenticated Limited Privilege Escalation via updatePassword vulnerability
<= 3.3.40
06/01/2026
Unauthenticated Cron Trigger due to Hardcoded Cron Key vulnerability
<= 3.3.30
10/11/2025
Sensitive Data Exposure vulnerability
<= 3.3.32
30/09/2025
Cross Site Request Forgery (CSRF) Vulnerability
<= 3.3.24
26/09/2025
Sensitive Data Exposure Vulnerability
<= 3.3.25
26/09/2025
Reflected Cross-Site Scripting via `user_ids` Parameter vulnerability
<= 3.3.23
18/09/2025
Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode vulnerability
<= 3.3.18
19/06/2025
Admin+ Stored XSS vulnerability
<= 3.2.98
19/05/2025
Authenticated (Author+) Arbitrary File Deletion vulnerability
<= 3.3.12
19/04/2025
Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload vulnerability
<= 3.3.12
17/04/2025
Authenticated (Author+) Path Traversal to Limited File Overwrite vulnerability
<= 3.3.08
12/03/2025
Unauthenticated Information Disclosure via Unprotected Directory vulnerability
<= 3.3.06
08/03/2025
Admin+ Stored XSS vulnerability
< 3.3.03
20/12/2024
Broken Access Control vulnerability
<= 3.3.03
19/12/2024
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 3.3.03
18/12/2024
Improper Authorization to Unauthenticated Download of Password-Protected Files vulnerability
<= 3.3.03
18/12/2024
Contributor+ Stored XSS vulnerability
< 3.3.00
30/10/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.2.97
31/07/2024
Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting vulnerability
<= 3.2.86
12/06/2024
Improper Authorization via protectMediaLibrary vulnerability
<= 3.2.89
12/06/2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 3.2.92
11/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode vulnerability
<= 3.2.93
05/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode vulnerability
<= 3.2.90
31/05/2024
File Password Lock Bypass vulnerability
<= 3.2.82
12/04/2024
Cross Site Scripting (XSS) vulnerability
<= 3.2.84
16/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.2.85
28/02/2024
Missing Authorization vulnerability
<= 3.2.84
28/02/2024
Broken Access Controls vulnerability
< 3.2.71
30/05/2023
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.2.70
15/05/2023
Unauthenticated Sensitive Information Disclosure vulnerability
5.0.0-6.2.9
13/04/2023
Contributor+ Stored XSS vulnerability
< 3.2.62
20/12/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.2.59
29/11/2022
Authenticated PHAR Deserialization vulnerability
<= 3.2.49
18/08/2022
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
<= 3.2.48
02/08/2022
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
<= 3.2.48
02/08/2022
Cross-Site Request Forgery (CSRF) vulnerability
<= 3.2.48
02/08/2022
Bypass IP Address Blocking Restriction vulnerability
<= 3.2.49
01/08/2022
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 3.2.46
01/07/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.2.43
27/06/2022
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.2.43
27/06/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.2.42
07/06/2022
Unauthenticated Brute Force of Files Master Key vulnerability
<= 3.2.38
16/03/2022
Sensitive Information Disclosure vulnerability
<= 3.2.24
02/02/2022
Authenticated SQL injection (SQLi) vulnerability to Reflected XSS vulnerability
<= 3.2.33
12/01/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 3.2.21
29/11/2021
Stored Cross-Site Scripting (XSS) vulnerability
<= 3.2.15
29/09/2021
Email Template Setting Update via Cross-Site Request Forgery (CSRF) vulnerability
<= 3.2.12
09/08/2021
Authenticated File Upload vulnerability
<= 3.1.24
29/07/2021
Multiple vulnerabilities
<= 2.9.96
16/06/2019
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 2.9.93
23/04/2019
Cross-Site Request Forgery (CSRF) vulnerability
<= 2.9.60
10/01/2018
Authenticated Arbitrary File Upload Vulnerability
<= 2.8.97
27/06/2017
Multiple Vulnerabilities
<= 2.8.7
19/01/2016
Stored XSS
<= 2.7.94
20/12/2015
Authenticated Stored XSS
<= 2.7.94
16/07/2015
XSS
<= 2.2.2
15/05/2015
Remote Code Execution
<= 2.7.4
15/12/2014
Multiple CSRF and XSS
<= 2.0.6
28/11/2014
Privilege Escalation
<= 2.7.2
24/11/2014
Arbitrary File Download
<= 1.0
04/11/2014
Persistent Cross Site Scripting
<= 2.5.8
08/12/2013
CSRF
<= 1.60
26/03/2013
Arbitrary File Upload
<= 0.2
30/07/2008