WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in CM Download Manager – Organize, Protect & Share Files in WordPress

Manage and protect your downloads in WordPress with secure access, categories, and powerful file sharing.

10Reported vulnerabilities
10Highest CVSS score
3.1.1Latest version
100+Active installs

What to do now

Update CM Download Manager – Organize, Protect & Share Files in WordPress to 3.0.0 or later. 10 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 23, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2014-8877 High 10 14.4% 2.0.3 and earlier
2.0.0 to 2.0.0 (inclusive)
2.0.1 to 2.0.1 (inclusive)
2.0.2 to 2.0.2 (inclusive)
2.0.4 December 5, 2014
CVE-2024-1962 High 8.8 0.5% Before 2.9.1 2.9.1 March 25, 2024
CVE-2022-3076 High 7.2 1.2% Before 2.8.6 2.8.6 September 26, 2022
CVE-2014-9129 Medium 6.8 1.5% 2.0.6 and earlier 2.0.7 December 5, 2014
CVE-2024-1231 Medium 6.8 0.2% Before 2.9.0 2.9.0 March 25, 2024
CVE-2020-27344 Medium 6.1 1.0% Before 2.8.0 2.8.0 October 21, 2020
CVE-2025-30910 Critical 9.1 0.6% 2.9.6 and earlier 3.0.0 March 27, 2025
CVE-2024-1232 Medium 4.8 0.2% Before 2.9.0 2.9.0 March 25, 2024
CVE-2020-24146 High 8.1 1.7% 2.7.0 to 2.7.0 (inclusive) 2.8.0 July 7, 2021
CVE-2020-24145 Medium 6.1 1.0% 2.7.0 to 2.7.0 (inclusive) 2.8.0 July 7, 2021

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.