plugin

Download Monitor Vulnerabilities

66 known security issues reported for the Download Monitor WordPress plugin. Most recent disclosed Aug 3, 2026.

1 critical 7 high 23 medium

Running Download Monitor on your site? Check whether your installed version is affected.

Scan your site free

Download Monitor <= 5.2.5 - Missing Authorization

medium

The Download Monitor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Aug 3, 2026

CVE-2026-16608 on NVD →

Download Monitor <= 5.1.9 - Authenticated (Author+) Arbitrary File Download

medium

The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.9. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
4.3
Affected:
up to 5.1.9
Fixed in:
5.1.10
Disclosed:
Apr 20, 2026

CVE-2026-39489 on NVD →

Download Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and Disabling

medium

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for u...

CVSS:
5.4
Affected:
up to 5.1.10
Fixed in:
5.1.11
Disclosed:
Apr 7, 2026

CVE-2026-4401 on NVD →

Download Monitor - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability

medium

Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability

CVSS:
5.3
Affected:
up to 5.1.7
Fixed in:
5.1.8
Disclosed:
Mar 30, 2026

Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id'

high

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by explo...

CVSS:
7.5
Affected:
up to 5.1.7
Fixed in:
5.1.8
Disclosed:
Mar 29, 2026

CVE-2026-3124 on NVD →

Download Monitor <= 5.1.8 - Authenticated (Contributor+) SQL Injection

medium

The Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
6.5
Affected:
up to 5.1.8
Fixed in:
5.1.9
Disclosed:
Mar 25, 2026

CVE-2026-39486 on NVD →

Download Monitor <= 5.0.22 - Authenticated (Contributor+) Local File Inclusion

high

The Download Monitor plugin for WordPress is vulnerable to Local File Inclusion via the get_template_part() function in versions up to, and including, 5.0.22. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the e...

CVSS:
8.8
Affected:
up to 5.0.22
Fixed in:
5.0.23
Disclosed:
May 7, 2025

CVE-2025-47439 on NVD →

Download Monitor [download-monitor] < 5.0.23

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor allows PHP Local File Inclusion. This issue affects Download Monitor: from n/a through 5.0.22.

Affected:
up to 5.0.23
Fixed in:
5.0.23
Disclosed:
May 7, 2025

CVE-2025-47439 on NVD →

Download Monitor [download-monitor] < 5.0.14

unknown

[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain userna...

Affected:
up to 5.0.14
Fixed in:
5.0.14
Disclosed:
Oct 30, 2024

CVE-2024-10399 on NVD →

Download Monitor <= 5.0.13 - Missing Authorization to Sensitive Information Exposure

medium

The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames a...

CVSS:
4.3
Affected:
up to 5.0.13
Fixed in:
5.0.14
Disclosed:
Oct 29, 2024

CVE-2024-10399 on NVD →

Download Monitor [download-monitor] < 5.0.13

unknown

[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to rev...

Affected:
up to 5.0.13
Fixed in:
5.0.13
Disclosed:
Oct 26, 2024

CVE-2024-10092 on NVD →

Download Monitor <= 5.0.12 - Missing Authorization to API Key Manipulation

medium

The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke e...

CVSS:
4.3
Affected:
up to 5.0.12
Fixed in:
5.0.13
Disclosed:
Oct 25, 2024

CVE-2024-10092 on NVD →

Download Monitor [download-monitor] < 4.7.52

unknown

[en] The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended...

Affected:
up to 4.7.52
Fixed in:
4.7.52
Disclosed:
Oct 16, 2024

CVE-2022-4972 on NVD →

Download Monitor [download-monitor] < 5.0.10

unknown

[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop functi...

Affected:
up to 5.0.10
Fixed in:
5.0.10
Disclosed:
Sep 26, 2024

CVE-2024-8552 on NVD →

Download Monitor <= 5.0.9 - Missing Authorization to Authenticated (Subscriber+) Shop Enable

medium

The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop functionali...

CVSS:
4.3
Affected:
up to 5.0.9
Fixed in:
5.0.10
Disclosed:
Sep 25, 2024

CVE-2024-8552 on NVD →

Download Monitor [download-monitor] < 4.9.14

unknown

[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.

Affected:
up to 4.9.14
Fixed in:
4.9.14
Disclosed:
May 30, 2024

CVE-2024-3269 on NVD →

Download Monitor <= 4.9.13 - Missing Authorization

medium

The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.

CVSS:
5.4
Affected:
up to 4.9.13
Fixed in:
4.9.14
Disclosed:
May 29, 2024

CVE-2024-3269 on NVD →

Download Monitor [download-monitor] < 4.9.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Mar 29, 2024

CVE-2024-30501 on NVD →

Download Monitor <= 4.9.4 - Authenticated (Admin+) SQL Injection

high

The Download Monitor plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter in all versions up to 4.9.5 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with a...

CVSS:
7.2
Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Jan 8, 2024

CVE-2024-30501 on NVD →

Download Monitor [download-monitor] < 4.9.5

unknown

Update the WordPress Download Monitor plugin to the latest available version (at least 4.9.5). WordFence discovered and reported this SQL Injection vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing inform...

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Jan 8, 2024

Download Monitor [download-monitor] < 4.9.5

unknown

The Download Monitor plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter in all versions up to 4.9.5 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with a...

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Jan 8, 2024

Download Monitor [download-monitor] < 4.7.70

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

Affected:
up to 4.7.70
Fixed in:
4.7.70
Disclosed:
Jan 8, 2024

CVE-2022-45354 on NVD →

Download Monitor [download-monitor] < 4.8.4

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.

Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Dec 20, 2023

CVE-2023-34007 on NVD →

Download Monitor [download-monitor] < 4.8.2

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.

Affected:
up to 4.8.2
Fixed in:
4.8.2
Disclosed:
Nov 13, 2023

CVE-2023-31219 on NVD →

Download Monitor [download-monitor] < 4.7.70

unknown

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.60. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to view use...

Affected:
up to 4.7.70
Fixed in:
4.7.70
Disclosed:
Jun 9, 2023

Download Monitor <= 4.8.3 - Authenticated(Subscriber+) Arbitrary File Upload via upload_file

high

The Download Monitor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and access controls on the 'upload_file' function in versions up to, and including, 4.8.3. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitr...

CVSS:
8.8
Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Jun 7, 2023

CVE-2023-34007 on NVD →

Download Monitor [download-monitor] < 4.8.4

unknown

The Download Monitor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and access controls on the 'upload_file' function in versions up to, and including, 4.8.3. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitr...

Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Jun 7, 2023

Download Monitor <= 4.8.1 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Download Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 4.8.1 via the trigger() function. This makes it possible for authenticated attackers with administrative privileges to make web requests to arbitrary locations originating from the web application an...

CVSS:
5.5
Affected:
up to 4.8.1
Fixed in:
4.8.2
Disclosed:
May 30, 2023

CVE-2023-31219 on NVD →

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

medium

The Download Monitor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.7.60 via REST API. This can allow unauthenticated attackers to extract sensitive data including user reports, download reports, and user data including email, role, id and other info (not passwo...

CVSS:
5.4
Affected:
up to 4.7.60
Fixed in:
4.7.70
Disclosed:
May 10, 2023

CVE-2022-45354 on NVD →

Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export

high

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for...

CVSS:
7.5
Affected:
up to 4.7.51
Fixed in:
4.7.52
Disclosed:
Nov 26, 2022

CVE-2022-4972 on NVD →

Download Monitor [download-monitor] < 4.7.52

unknown

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for...

Affected:
up to 4.7.52
Fixed in:
4.7.52
Disclosed:
Nov 26, 2022

Download Monitor <= 4.7.2 - Authenticated Directory Traversal to Sensitive Information Exposure

medium

The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.7.2 via the list_files function. This allows users with manage_downloads permissions to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
4.9
Affected:
up to 4.7.2
Fixed in:
4.7.3
Disclosed:
Nov 1, 2022

Download Monitor [download-monitor] < 4.7.3

unknown

The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.7.2 via the list_files function. This allows users with manage_downloads permissions to read the contents of arbitrary files on the server, which can contain sensitive information.

Affected:
up to 4.7.3
Fixed in:
4.7.3
Disclosed:
Nov 1, 2022

Download Monitor [download-monitor] < 4.5.98

unknown

[en] The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

Affected:
up to 4.5.98
Fixed in:
4.5.98
Disclosed:
Oct 10, 2022

CVE-2022-2981 on NVD →

Download Monitor <= 4.5.97 - Authenticated (Administrator+) Arbitrary File Download

medium

The Download Monitor plugin for WordPress is vulnerable to arbitrary file downloads due to not verifying that downloaded files reside within the blog directory in versions up to, and including, 4.5.97. This makes it possible for authenticated attackers, with administrator-level permissions and above, to download arbitr...

CVSS:
6.8
Affected:
up to 4.5.97
Fixed in:
4.5.98
Disclosed:
Sep 19, 2022

CVE-2022-2981 on NVD →

Download Monitor [download-monitor] < 4.5.91

unknown

[en] The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

Affected:
up to 4.5.91
Fixed in:
4.5.91
Disclosed:
Jul 17, 2022

CVE-2022-2222 on NVD →

Download Monitor <= 4.5.9 - Authenticated Arbitrary File Download

medium

The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

CVSS:
4.9
Affected:
up to 4.5.9
Fixed in:
4.5.91
Disclosed:
Jun 27, 2022

CVE-2022-2222 on NVD →

Download Monitor [download-monitor] < 4.4.7

unknown

[en] Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

Affected:
up to 4.4.7
Fixed in:
4.4.7
Disclosed:
Jan 28, 2022

CVE-2021-23174 on NVD →

Download Monitor [download-monitor] < 4.4.7

unknown

[en] Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible...

Affected:
up to 4.4.7
Fixed in:
4.4.7
Disclosed:
Jan 28, 2022

CVE-2021-31567 on NVD →

Download Monitor [download-monitor] < 4.4.7

unknown

[en] Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).

Affected:
up to 4.4.7
Fixed in:
4.4.7
Disclosed:
Jan 14, 2022

CVE-2021-36920 on NVD →

Download Monitor [download-monitor] < 4.4.5

unknown

[en] The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

Affected:
up to 4.4.5
Fixed in:
4.4.5
Disclosed:
Jan 3, 2022

CVE-2021-24786 on NVD →

Download Monitor <= 4.4.6 - Authenticated (Admin+) Arbitrary File Download

medium

Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to es...

CVSS:
6.8
Affected:
up to 4.4.6
Fixed in:
4.4.7
Disclosed:
Oct 29, 2021

CVE-2021-31567 on NVD →

Download Monitor <= 4.4.6 - Reflected Cross-Site Scripting

medium

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).

CVSS:
6.1
Affected:
up to 4.4.6
Fixed in:
4.4.7
Disclosed:
Oct 29, 2021

CVE-2021-36920 on NVD →

Download Monitor <= 4.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

CVSS:
5.5
Affected:
up to 4.4.6
Fixed in:
4.4.7
Disclosed:
Oct 29, 2021

CVE-2021-23174 on NVD →

Download Monitor <= 4.4.4 - Admin+ SQL Injection via orderby parameter

high

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

CVSS:
7.2
Affected:
up to 4.4.5
Fixed in:
4.4.5
Disclosed:
Oct 20, 2021

CVE-2021-24786 on NVD →

Download Monitor [download-monitor] < 1.7.1

unknown

[en] The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Aug 13, 2019

CVE-2015-9296 on NVD →

Download Monitor <= 1.9.6 - Missing Authorization

medium

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the delete_logs() and export_logs() functions in versions up to, and including, 1.9.6. This makes it possible for unauthenticated attackers to delete and export several log types.

CVSS:
6.5
Affected:
up to 1.9.6
Fixed in:
1.9.7
Disclosed:
May 5, 2017

Download Monitor [download-monitor] < 1.9.7

unknown

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the delete_logs() and export_logs() functions in versions up to, and including, 1.9.6. This makes it possible for unauthenticated attackers to delete and export several log types.

Affected:
up to 1.9.7
Fixed in:
1.9.7
Disclosed:
May 5, 2017

Download Monitor [download-monitor] < 1.6.4

unknown

This plugin is prone to an authenticated directory listing vulnerability. It allows attackers list sever side files and directories. Update the plugin.

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Aug 11, 2016

Download Monitor [download-monitor] < 1.7.1

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
May 15, 2015

Download Monitor <= 1.6.4 - Reflected Cross-Site Scripting

medium

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...

CVSS:
6.1
Affected:
up to 1.6.5, 1.7.0 – 1.7.0
Fixed in:
1.6.5
Disclosed:
Apr 20, 2015

Download Monitor < 1.7.1 - Reflected Cross-Site Scripting

medium

The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.

CVSS:
6.1
Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Apr 20, 2015

CVE-2015-9296 on NVD →

Download Monitor [download-monitor] <= 1.6.4

unknown

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Apr 20, 2015

Download Monitor <= 1.6.3 - Directory Listing to Information Disclosure

medium

The Download Monitor plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.6.3 via the 'dir' parameter. This can allow authenticated attackers to extract sensitive data including directories and otherwise restricted server-side filenames.

CVSS:
5.3
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Mar 8, 2015

Download Monitor [download-monitor] < 1.6.4

unknown

The Download Monitor plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.6.3 via the 'dir' parameter. This can allow authenticated attackers to extract sensitive data including directories and otherwise restricted server-side filenames.

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Mar 8, 2015

Download Monitor [download-monitor] < 3.3.5.9

unknown

[en] Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.

Affected:
up to 3.3.5.9
Fixed in:
3.3.5.9
Disclosed:
Sep 4, 2014

CVE-2012-4768 on NVD →

Download Monitor [download-monitor] < 3.3.6.2

unknown

[en] Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.

Affected:
up to 3.3.6.2
Fixed in:
3.3.6.2
Disclosed:
Aug 9, 2013

CVE-2013-3262 on NVD →

Download Monitor [download-monitor] < 3.3.6.2

unknown

[en] Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.

Affected:
up to 3.3.6.2
Fixed in:
3.3.6.2
Disclosed:
Aug 9, 2013

CVE-2013-5098 on NVD →

Download Monitor < 3.3.6.2 - Cross-Site Scripting via sort Parameter

high

Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.

CVSS:
7.2
Affected:
up to 3.3.6.2
Fixed in:
3.3.6.2
Disclosed:
Jul 23, 2013

CVE-2013-5098 on NVD →

Download Monitor < 3.3.6.2 - Cross-Site Scripting via p Parameter

medium

Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.

CVSS:
6.1
Affected:
up to 3.3.6.2
Fixed in:
3.3.6.2
Disclosed:
Jul 22, 2013

CVE-2013-3262 on NVD →

Download Monitor <= 3.3.5.8 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.

CVSS:
6.1
Affected:
up to 3.3.5.8
Fixed in:
3.3.5.9
Disclosed:
Sep 6, 2012

CVE-2012-4768 on NVD →

Download Monitor [download-monitor] < 2.0.9

unknown

[en] SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Apr 30, 2008

CVE-2008-2034 on NVD →

Download Monitor <= 2.0.6 - Unauthenticated SQL Injection

critical

SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS:
9.8
Affected:
up to 2.0.6
Fixed in:
2.0.9
Disclosed:
Apr 28, 2008

CVE-2008-2034 on NVD →

Download Monitor [download-monitor] < 1.2.1

unknown

[en] SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Apr 2, 2008

CVE-2008-1646 on NVD →

Download Monitor [download-monitor] < 1.6.4

unknown

Directory listing vulnerability that can lead to information disclosure. Authenticated users can list sever side files and directories.

Affected:
up to 1.6.4
Fixed in:
1.6.4

Download Monitor [download-monitor] < 1.9.7

unknown

An Unauthenticated attacker can export download logs from the Plugin. Which includes: Download ID, Version ID, Filename, User ID, User Login, User Email, User IP, User Agent, Date, Status. The information could potentially be used to mount further attacks or just collect contact information.

Affected:
up to 1.9.7
Fixed in:
1.9.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database