Download Monitor <= 5.1.9 - Authenticated (Author+) Arbitrary File Download
Download Monitor
Minimum safe version
5.1.11
Update to 5.1.11 or later to address 38 fixable vulnerabilities
CVE-2026-39486
Download Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and Disabling
Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id'
CVE-2025-47439
CVE-2024-10399
CVE-2024-10092
CVE-2022-4972
CVE-2024-8552
CVE-2024-3269
CVE-2024-30501
WordPress Download Monitor Plugin < 4.9.5 is vulnerable to SQL Injection
Download Monitor <= 4.9.4 - Authenticated (Admin+) SQL Injection
CVE-2023-34007
Download Monitor <= 4.7.60 - Missing Authorization to Authenticated Data Export
Download Monitor <= 4.8.3 - Authenticated(Subscriber+) Arbitrary File Upload via upload_file
CVE-2023-31219
CVE-2022-45354
Download Monitor <= 1.6.3 - Directory Listing to Information Disclosure
Download Monitor <= 1.6.4 - Reflected Cross-Site Scripting
Download Monitor <= 1.9.6 - Missing Authorization
Download Monitor <= 4.7.2 - Authenticated Directory Traversal to Sensitive Information Exposure
Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export
Download Monitor < 1.6.4 - Authenticated Directory Listing
Download Monitor < 1.9.7 - Unauthenticated Downloading of Logs
CVE-2022-2981
CVE-2022-2222
WordPress Download Monitor Plugin <= 1.7.0 - Cross Site Scripting
WordPress Download Monitor Plugin <= 1.6.3 - Authenticated Directory Listing
CVE-2008-1646
CVE-2008-2034
CVE-2013-5098
CVE-2013-3262
CVE-2012-4768
CVE-2015-9296
CVE-2021-24786
CVE-2021-36920
CVE-2021-31567
CVE-2021-23174