WordPress security by component
Download Monitor
Plugin description
Download Monitor is a WordPress component with 24 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.9.
Plugin slug:
download-monitorLatest vulnerability
CVE-2026-39489: Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.1.9.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2026-39489
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.1.9.
|
5.1.10 |
CVE4.4
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39486
Download Monitor: SQL injection
Download Monitor is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.1.8.
|
5.1.9 |
CVE8.5
NVDPending
|
| Apr 08, 2026 |
CVE-2026-4401
Download Monitor: Cross-site request forgery
Download Monitor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 5.1.10.
|
> 5.1.10 |
CVE5.4
NVDPending
|
| Mar 30, 2026 |
CVE-2026-3124
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.1.7.
|
> 5.1.7 |
CVE7.5
NVDPending
|
| May 07, 2025 |
CVE-2025-47439
Download Monitor: Filesystem traversal
Download Monitor is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Oct 30, 2024 |
CVE-2024-10399
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 26, 2024 |
CVE-2024-10092
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 16, 2024 |
CVE-2022-4972
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Sep 26, 2024 |
CVE-2024-8552
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 30, 2024 |
CVE-2024-3269
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 29, 2024 |
CVE-2024-30501
Download Monitor: SQL injection
Download Monitor is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Jan 08, 2024 |
CVE-2022-45354
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Dec 20, 2023 |
CVE-2023-34007
Download Monitor: Dangerous file upload
Download Monitor is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Nov 13, 2023 |
CVE-2023-31219
Download Monitor: Server-side request forgery
Download Monitor is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.1
NVD4.9
|
| Oct 10, 2022 |
CVE-2022-2981
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Jul 17, 2022 |
CVE-2022-2222
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Jan 28, 2022 |
CVE-2021-31567
Download Monitor: A security weakness
Download Monitor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.8
NVD6.8
|
| Jan 28, 2022 |
CVE-2021-23174
Download Monitor: Cross-site scripting
Download Monitor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.4
NVD4.8
|
| Jan 14, 2022 |
CVE-2021-36920
Download Monitor: Cross-site scripting
Download Monitor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD5.4
|
| Jan 03, 2022 |
CVE-2021-24786
Download Monitor: SQL injection
Download Monitor is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Aug 13, 2019 |
CVE-2015-9296
Download Monitor: Cross-site scripting
Download Monitor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Sep 04, 2014 |
CVE-2012-4768
Download Monitor: Cross-site scripting
Download Monitor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Aug 09, 2013 |
CVE-2013-5098
Download Monitor: Cross-site scripting
Download Monitor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Aug 09, 2013 |
CVE-2013-3262
Download Monitor: Cross-site scripting
Download Monitor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|