WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Simple Download Monitor

Easily manage downloadable files and monitor downloads of your digital files from your WordPress site.

17Reported vulnerabilities
9.9Highest CVSS score
4.1.0Latest version
20,000+Active installs

What to do now

Update Simple Download Monitor to 4.0.6 or later. 17 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 14, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24693 Critical 9 1.3% Before 3.9.5 3.9.5 November 8, 2021
CVE-2021-24696 High 8.8 0.6% Before 3.9.9 3.9.9 January 24, 2022
CVE-2021-24695 High 7.5 1.7% Before 3.9.5 3.9.5 November 8, 2021
CVE-2021-24692 Medium 6.5 1.4% Before 3.9.5 3.9.5 March 14, 2022
CVE-2021-24697 Medium 6.1 0.8% Before 3.9.5 3.9.5 November 8, 2021
WF-f5ad74c5-93ba-414c-98ad-0987547f172f Critical 9.9 3.2.8 and earlier 3.2.9 January 19, 2016
CVE-2018-5213 Medium 5.4 1.0% 3.5.4 to 3.5.4 (inclusive) 3.5.4 January 4, 2018
CVE-2018-5212 Medium 5.4 1.0% 3.5.4 to 3.5.4 (inclusive) 3.5.4 January 4, 2018
CVE-2021-24694 Medium 5.4 0.6% Before 3.9.11 3.9.11 January 24, 2022
CVE-2020-5651 High 8.8 1.5% 3.8.8 and earlier 3.8.9 October 21, 2020
CVE-2021-24698 Medium 4.3 0.7% Before 3.9.6 3.9.6 November 8, 2021
CVE-2025-8977 Medium 6.5 0.3% 0 to 3.9.33 (inclusive) 3.9.34 August 28, 2025
CVE-2026-2383 Medium 6.4 0.2% 0 to 4.0.5 (inclusive) 4.0.6 February 27, 2026
CVE-2025-58197 Medium 6.4 0.2% 3.9.34 and earlier 3.9.35 August 27, 2025
CVE-2020-5650 Medium 6.1 0.9% 3.3.8 and earlier 3.3.9 October 21, 2020
CVE-2025-24663 Medium 4.9 0.6% 3.9.25 and earlier 3.9.26 January 24, 2025
WF-70493df9-82b8-4160-8d75-889fada7541f Medium 4.3 3.9.5 and earlier 3.9.6 October 5, 2021

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.