CVE-2014-9260: w3eden Download Manager
High severity, CVSS 8.8. EPSS: 11.1% chance of exploitation in the next 30 days.
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
Affected products
- w3eden Download Manager: before 2.7.3 (fixed in 2.7.3)
Published 2017-08-07. Last modified 2026-06-17.