PLUGIN SECURITY

Is Download Monitor safe?

Powerful Download Manager Plugin for WordPress

What this plugin does

  • Slug: download-monitor
  • Author: WP Chill
  • 80000+ active installs
  • 90/100 rating (524 reviews on wordpress.org)
  • 7122898 all-time downloads
  • On WordPress.org since 2008-03-12

digital storedownload managerecommercefile managerpassword protection

Maintenance status

  • Latest known version: 5.2.7
  • Last updated: 2026-08-14 8:45am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

27 known CVEs on file for Download Monitor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16608 Download Monitor [download-monitor] < 5.2.6 Missing Authorization Unknown < 5.2.6 5.2.6 2026-08-03 ✓ fixed in latest
CVE-2026-39489 Download Monitor [download-monitor] < 5.1.10 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.4 < 5.1.10 5.1.10 2026-04-20 ✓ fixed in latest
CVE-2026-39486 Download Monitor [download-monitor] < 5.1.9 High 8.5 < 5.1.9 5.1.9 2026-03-25 ✓ fixed in latest
CVE-2025-47439 Download Monitor [download-monitor] < 5.0.23 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 5.0.23 5.0.23 2025-05-07 ✓ fixed in latest
CVE-2024-10399 Download Monitor [download-monitor] < 5.0.14 Missing Authorization Medium 4.3 < 5.0.14 5.0.14 2024-10-29 ✓ fixed in latest
CVE-2024-10092 Download Monitor [download-monitor] < 5.0.13 Missing Authorization Medium 4.3 < 5.0.13 5.0.13 2024-10-25 ✓ fixed in latest
CVE-2024-8552 Download Monitor [download-monitor] < 5.0.10 Missing Authorization Medium 4.3 < 5.0.10 5.0.10 2024-09-25 ✓ fixed in latest
CVE-2024-3269 Download Monitor [download-monitor] < 4.9.14 Improper Authorization Medium 5.4 < 4.9.14 4.9.14 2024-05-29 ✓ fixed in latest
+ 34 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-30501 Download Monitor [download-monitor] < 4.9.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 4.9.5 4.9.5 2024-01-08 ✓ fixed in latest
Download Monitor [download-monitor] < 4.9.5 Unknown < 4.9.5 4.9.5 2024-01-08 ✓ fixed in latest
Download Monitor [download-monitor] < 4.7.70 Unknown < 4.7.70 4.7.70 2023-06-09 ✓ fixed in latest
CVE-2023-34007 Download Monitor [download-monitor] < 4.8.4 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 4.8.4 4.8.4 2023-06-07 ✓ fixed in latest
CVE-2023-31219 Download Monitor [download-monitor] < 4.8.2 Server-Side Request Forgery (SSRF) Medium 4.1 < 4.8.2 4.8.2 2023-05-30 ✓ fixed in latest
CVE-2022-45354 Download Monitor [download-monitor] < 4.7.70 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 4.7.70 4.7.70 2023-05-10 ✓ fixed in latest
CVE-2022-4972 Download Monitor [download-monitor] < 4.7.52 Missing Authorization High 7.5 < 4.7.52 4.7.52 2022-11-26 ✓ fixed in latest
Download Monitor [download-monitor] < 4.7.3 Unknown < 4.7.3 4.7.3 2022-11-01 ✓ fixed in latest
CVE-2022-2981 Download Monitor [download-monitor] < 4.5.98 Files or Directories Accessible to External Parties Medium 4.9 < 4.5.98 4.5.98 2022-09-19 ✓ fixed in latest
CVE-2022-2222 Download Monitor [download-monitor] < 4.5.91 Files or Directories Accessible to External Parties Medium 4.9 < 4.5.91 4.5.91 2022-06-27 ✓ fixed in latest
CVE-2021-23174 Download Monitor [download-monitor] < 4.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.4.7 4.4.7 2021-10-29 ✓ fixed in latest
CVE-2021-31567 Download Monitor [download-monitor] < 4.4.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.8 < 4.4.7 4.4.7 2021-10-29 ✓ fixed in latest
CVE-2021-36920 Download Monitor [download-monitor] < 4.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.4.7 4.4.7 2021-10-29 ✓ fixed in latest
CVE-2021-24786 Download Monitor [download-monitor] < 4.4.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 4.4.5 4.4.5 2021-10-20 ✓ fixed in latest
Download Monitor [download-monitor] < 1.9.7 Unknown < 1.9.7 1.9.7 2017-05-05 ✓ fixed in latest
Download Monitor [download-monitor] < 1.6.4 Unknown < 1.6.4 1.6.4 2016-08-11 ✓ fixed in latest
Download Monitor [download-monitor] < 1.7.1 Unknown < 1.7.1 1.7.1 2015-05-15 ✓ fixed in latest
CVE-2015-9296 Download Monitor [download-monitor] < 1.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.7.1 1.7.1 2015-04-20 ✓ fixed in latest
Download Monitor [download-monitor] <= 1.6.4 Unknown < 1.6.4 1.6.4 2015-04-20 ✓ fixed in latest
Download Monitor [download-monitor] < 1.6.4 Unknown < 1.6.4 1.6.4 2015-03-08 ✓ fixed in latest
CVE-2013-5098, CVE-2013-3262 Download Monitor [download-monitor] < 3.3.6.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.3.6.2 3.3.6.2 2013-07-23 ✓ fixed in latest
CVE-2013-3262 Download Monitor [download-monitor] < 3.3.6.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.3.6.2 3.3.6.2 2013-04-22 ✓ fixed in latest
CVE-2012-4768 Download Monitor [download-monitor] < 3.3.5.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.3.5.9 3.3.5.9 2012-08-30 ✓ fixed in latest
CVE-2008-2034 Download Monitor [download-monitor] < 2.0.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 2.0.9 2.0.9 2008-04-28 ✓ fixed in latest
CVE-2008-1646 Download Monitor [download-monitor] < 1.2.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 1.2.1 1.2.1 2008-03-31 ✓ fixed in latest
Download Monitor [download-monitor] < 5.1.8 Unknown < 5.1.8 5.1.8 0000-00-00 ✓ fixed in latest
Download Monitor [download-monitor] < 5.1.11 Medium 5.4 < 5.1.11 5.1.11 0000-00-00 ✓ fixed in latest
Download Monitor [download-monitor] < 1.9.7 Unknown < 1.9.7 1.9.7 ✓ fixed in latest
Download Monitor [download-monitor] < 1.6.4 Unknown < 1.6.4 1.6.4 ✓ fixed in latest
Download Monitor < 1.6.4 - Authenticated Directory Listing Unknown < 1.6.4 1.6.4 ✓ fixed in latest
Download Monitor < 1.9.7 - Unauthenticated Downloading of Logs Unknown < 1.9.7 1.9.7 ✓ fixed in latest
Download Monitor < 4.9.5 - Authenticated (Admin+) SQL Injection Unknown < 4.9.5 4.9.5 ✓ fixed in latest
CVE-2026-3124 Download Monitor < 5.1.8 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' Unknown < 5.1.8 5.1.8 ✓ fixed in latest
CVE-2026-4401 Download Monitor < 5.1.11 - Cross-Site Request Forgery to Download Path Deletion and Disabling Unknown < 5.1.11 5.1.11 ✓ fixed in latest

How to fix it

Keep Download Monitor updated — 5.2.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.