W3 Eden, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with Download Manager.
Products
Clear product- WordPress Download Manager4 vulnerabilities
- Download Manager (WordPress plugin)3 vulnerabilities
- Download Manager2 vulnerabilities
- Premium Packages1 vulnerability
- Pricing Table (WordPress plugin)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-29114MEDIUM | WordPress Download Manager plugin <= 3.2.84 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84. CWE-79Mar 19, 2024 | CVSS6.5v3.1 | EPSS0.337% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-45836HIGH | WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions. | CVSS7.1v3.1 | EPSS0.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |