Known Vulnerabilities for Download Shortcode by Werdswords
Listed below are 1 of the newest known vulnerabilities associated with "Download Shortcode" by "Werdswords".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-5357 json | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_m... | Not Provided | 2026-04-09 | 2026-04-09 |
| CVE-2026-4278 json | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in... | Not Provided | 2026-03-26 | 2026-04-08 |
| CVE-2025-11809 json | The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode in a... | Not Provided | 2025-10-22 | 2026-04-08 |
| CVE-2024-12453 json | The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd-widg... | Not Provided | 2025-01-07 | 2026-04-08 |
| CVE-2024-5966 json | The Grey Opaque theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme... | Not Provided | 2024-06-22 | 2026-04-08 |
| CVE-2024-4160 json | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' s... | Not Provided | 2024-05-31 | 2026-04-08 |
| CVE-2024-4001 json | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_for... | Not Provided | 2024-06-05 | 2026-04-08 |
| CVE-2024-3230 json | The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-attachm... | Not Provided | 2024-06-04 | 2026-04-08 |
| CVE-2023-6954 json | The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in a... | Not Provided | 2024-03-13 | 2026-04-08 |
| CVE-2022-1985 json | The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.... | Not Provided | 2022-06-13 | 2026-04-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Werdswords | Download Shortcode | 1.1 | |||
| Application | Werdswords | Download Shortcode | 1.0 | |||
| Application | Werdswords | Download Shortcode | 0.2.3 | |||
| Application | Werdswords | Download Shortcode | 0.2.2 | |||
| Application | Werdswords | Download Shortcode | 0.2 | |||
| Application | Werdswords | Download Shortcode | 0.1 |