Download Monitor
Vendor:
First CVE: Jan 3, 2022 · Active for 4 years
20
Total CVEs
More Total CVEs than 95% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Download Monitor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 3, 2022
4 years ago
Most Recent CVE
Jun 15, 2026
43 days ago
CVE Severity & Scoring
Download Monitor20 CVEs
60%
40%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High2 (10.0%)
Unknown0 (0.0%)
User Interaction
None17 (85.0%)
Unknown0 (0.0%)
Required3 (15.0%)
Privileges Required
Low8 (40.0%)
High8 (40.0%)
None4 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23174MEDIUM Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, & | Jan 28, 2022 | 4.8 | 64 | NO | NO |
CVE-2021-24786HIGH The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leadi | Jan 3, 2022 | 7.2 | 52 | NO | YES |
CVE-2022-45354HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60. | Jan 8, 2024 | 7.5 | 50 | NO | YES |
CVE-2026-39486HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This iss | Apr 8, 2026 | 8.5 | 29 | NO | NO |
CVE-2026-3124HIGH The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to mis | Mar 30, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-4401MEDIUM The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.p | Apr 8, 2026 | 5.4 | 24 | NO | NO |
CVE-2021-31567MEDIUM Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensi | Jan 28, 2022 | 6.8 | 23 | NO | NO |
CVE-2022-4972HIGH The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, | Oct 16, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-34007HIGH Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. | Dec 20, 2023 | 8.8 | 22 | NO | NO |
CVE-2025-47439HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local | May 7, 2025 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.0% of CVEs· 97th percentile
ExploitDB
1 CVE
5.0% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Download Monitor
Top CWEs
Versions
No cataloged versions.