CVE-2014-9260: w3eden Download Manager

High severity, CVSS 8.8. EPSS: 11.1% chance of exploitation in the next 30 days.

The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.

Affected products

  • w3eden Download Manager: before 2.7.3 (fixed in 2.7.3)

Published 2017-08-07. Last modified 2026-06-17.