Download Monitor

Download Monitor has 30 disclosed vulnerabilities in the WordSec catalog, reported between 2008 and 2026; all 30 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 7 high. 2026 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (23%). Other recurring categories include Missing Authorization, SQL Injection.

Every one of the 30 issues recorded for Download Monitor has a vendor fix available, so running the current release closes all known holes.

21 independent researchers contributed these findings, most of them (3) reported by Trương Hữu Phúc (truonghuuphuc). Download Monitor is installed on roughly 80,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891012.03.2008Today28.04.20089.8Download Monitor <= 2.0.6 - Unauthenticated SQL Injection CVSS 9.8 · 28.04.200806.09.20126.1Download Monitor <= 3.3.5.8 - Reflected Cross-Site Scripting CVSS 6.1 · 06.09.201222.07.20136.1Download Monitor < 3.3.6.2 - Cross-Site Scripting via p Parameter CVSS 6.1 · 22.07.201323.07.20137.2Download Monitor < 3.3.6.2 - Cross-Site Scripting via sort Parameter CVSS 7.2 · 23.07.201308.03.20155.3Download Monitor <= 1.6.3 - Directory Listing to Information Disclosure CVSS 5.3 · 08.03.201520.04.20156.1Download Monitor < 1.7.1 - Reflected Cross-Site Scripting CVSS 6.1 · 20.04.20156.1Download Monitor <= 1.6.4 - Reflected Cross-Site Scripting CVSS 6.1 · 20.04.201505.05.20176.5Download Monitor <= 1.9.6 - Missing Authorization CVSS 6.5 · 05.05.201720.10.20217.2Download Monitor <= 4.4.4 - Admin+ SQL Injection via orderby parameter CVSS 7.2 · 20.10.202129.10.20216.8Download Monitor <= 4.4.6 - Authenticated (Admin+) Arbitrary File Download CVSS 6.8 · 29.10.20215.5Download Monitor <= 4.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 5.5 · 29.10.20216.1Download Monitor <= 4.4.6 - Reflected Cross-Site Scripting CVSS 6.1 · 29.10.202127.06.20224.9Download Monitor <= 4.5.9 - Authenticated Arbitrary File Download CVSS 4.9 · 27.06.202219.09.20226.8Download Monitor <= 4.5.97 - Authenticated (Administrator+) Arbitrary File Download CVSS 6.8 · 19.09.202201.11.20224.9Download Monitor <= 4.7.2 - Authenticated Directory Traversal to Sensitive Information Exposure CVSS 4.9 · 01.11.202226.11.20227.5Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export CVSS 7.5 · 26.11.202210.05.20235.4Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API CVSS 5.4 · 10.05.202330.05.20235.5Download Monitor <= 4.8.1 - Authenticated (Admin+) Server-Side Request Forgery CVSS 5.5 · 30.05.202307.06.20238.8Download Monitor <= 4.8.3 - Authenticated(Subscriber+) Arbitrary File Upload via upload_file CVSS 8.8 · 07.06.202308.01.20247.2Download Monitor <= 4.9.4 - Authenticated (Admin+) SQL Injection CVSS 7.2 · 08.01.202429.05.20245.4Download Monitor <= 4.9.13 - Missing Authorization CVSS 5.4 · 29.05.202425.09.20244.3Download Monitor <= 5.0.9 - Missing Authorization to Authenticated (Subscriber+) Shop Enable CVSS 4.3 · 25.09.202425.10.20244.3Download Monitor <= 5.0.12 - Missing Authorization to API Key Manipulation CVSS 4.3 · 25.10.202429.10.20244.3Download Monitor <= 5.0.13 - Missing Authorization to Sensitive Information Exposure CVSS 4.3 · 29.10.202407.05.20258.8Download Monitor <= 5.0.22 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 07.05.202525.03.20266.5Download Monitor <= 5.1.8 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 25.03.202629.03.20267.5Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' CVSS 7.5 · 29.03.202607.04.20265.4Download Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and Disabling CVSS 5.4 · 07.04.202620.04.20264.3Download Monitor <= 5.1.9 - Authenticated (Author+) Arbitrary File Download CVSS 4.3 · 20.04.202603.08.20265.3Download Monitor <= 5.2.5 - Missing Authorization CVSS 5.3 · 03.08.2026

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage100%
Open

0

Fixed

30

Get automatic notifications for all Download Monitor vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2008-2034

Download Monitor <= 2.0.6 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

30 records
2026-08-03 00:00CVE-2026-16608
5.3
Medium
Anirudh GuptaYes
2026-04-20 00:00CVE-2026-39489
4.3
Medium
darooYes
2026-04-07 11:17CVE-2026-4401
5.4
Medium
alex_henry20Yes
2026-03-29 12:42CVE-2026-3124
7.5
High
bashuYes
2026-03-25 00:00CVE-2026-39486
6.5
Medium
darooYes
2025-05-07 00:00CVE-2025-47439
8.8
High
João Pedro Soares de AlcântaraYes
2024-10-29 17:11CVE-2024-10399
4.3
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2024-10-25 19:31CVE-2024-10092
4.3
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2024-09-25 00:00CVE-2024-8552
4.3
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2024-05-29 14:49CVE-2024-3269
5.4
Medium
Arkadiusz HydzikYes
Showing 1–10 of 30 reports
Download Monitor banner
Latestv5.2.9

Download Monitor

WP Chill

Author

WP Chill

4.5(524)
90/100
Last Updated
2026-09-07 (7d ago)
Active Installs
80,000+
Downloads
7,194,071
Requires WP
6.4+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2008-03-12 (19y ago)

Powerful Download Manager Plugin for WordPress Download Monitor is a powerful download manager plugin for handling downloadable files, adding download links to your posts or pages, and tracking downloads. Download Monitor has been featured on the websites of some of the most popular and leading businesses in the WordPress ecosystem, such as WPBeginner, Pagely, Jilt, WP Fusion & Kinsta. See how easy it is to list a download on your WordPress site Download Monitor Extensions available when purchasing a Pro plan Buttons: Create beautiful, fully customizable download buttons for your files. Downloading Page: Serve your downloads from a separate page. Google Drive: Lets you use the files hosted on your Google Drive as Download Monitor files. Advanced Access Manager: Create advanced download limitations per download and on a global level. Email Notification: Trigger an email notification whenever one of your files is downloaded. Document Library Manage: Display files in fast, searchable tables or grids with sorting, filters, and flexible styling. Your documents, easy to find. Lock downloads option: Set restrictions to your download functionality using MailChimp Lock, Email Lock, CAPTCHA, Gravity Forms Gated Content: easily create a download gate with Gravity Forms. Require users to fill-in a form before accessing a download. Ninja Forms Lock: if you are an user of Ninja Forms, you can also use this to require users to fill-in of a form before accesing a download. WPForms Gated Content: gate your downloads by first requesting users to submit a form build using WPForms. Contact Form 7 Lock: request the submission of a Contact Form 7 form before providing access to the download. Documentation We have a large Knowledge Base on our Download Monitor website that contains documentation about how to how to setup and use Download Monitor. How-to Guides Are you a new Download Monitor user? Read these articles on how to get your files ready for download with Download Monitor: How to install Download Monitor How to add your first download in Download Monitor How to list your first download on your website with the download shortcode More advanced topics that a lot of people find interesting: Learn more about the different ways you can style your download buttons Learn more about how to customize your download buttons Learn more about what actions and filters are available in Download Monitor Contributing and reporting bugs You can contribute code to this plugin via GitHub: https://github.com/WPChill/download-monitor You can contribute localizations via Transifex https://www.transifex.com/projects/p/download-monitor/ Help & Support Search our extensive knowledge base for documentation about installing the plugin/the extensions, available settings and how to use them. Browse Download monitor’s WordPress forum to find answers to your queries or create a new topic. Contact us directly for support. 3rd party or external service disclaimer The plugin connects to our website through an API call (https://download-monitor.com/?dlm-all-extensions=true) in order to request a list of available extensions. IT DOES NOT SEND ANY DATA NOR DO WE COLLECT INFORMATION FROM THE REQUEST Our privacy policy can be found at this URL https://download-monitor.com/privacy-policy/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C