
CM Download Manager – Organize, Protect & Share Files in WordPress Security & Risk Analysis
wordpress.org/plugins/cm-download-managerManage and protect your downloads in WordPress with secure access, categories, and powerful file sharing.
Is CM Download Manager – Organize, Protect & Share Files in WordPress Safe to Use in 2026?
Generally Safe
Score 87/100CM Download Manager – Organize, Protect & Share Files in WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The cm-download-manager plugin v3.1.0 presents a mixed security posture. While it demonstrates good practices such as 100% prepared SQL statements and the absence of dangerous functions or file operations, significant concerns remain. The presence of three unprotected AJAX handlers drastically increases the attack surface, offering potential entry points for attackers. The taint analysis, although reporting no critical or high severity flows, did identify two flows with unsanitized paths, which could indicate potential path traversal vulnerabilities if not properly handled by the application logic, despite the absence of explicit file operation calls in static analysis. Furthermore, a history of 10 known CVEs, including critical and high severity issues like Path Traversal, CSRF, and Code Injection, suggests a recurring pattern of security weaknesses in past versions. The most recent vulnerability listed is dated 2025-03-27, which is in the future, implying either an error in the data or a known upcoming vulnerability that is currently unpatched from a historical perspective. The plugin's significant vulnerability history, coupled with the unprotected AJAX endpoints, warrants caution and diligent monitoring for new vulnerabilities.
Key Concerns
- 3 AJAX handlers without auth checks
- 46% of outputs properly escaped
- 2 flows with unsanitized paths
- 2 critical CVEs historically
- 2 high CVEs historically
- 6 medium CVEs historically
CM Download Manager – Organize, Protect & Share Files in WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
CM Download Manager <= 2.9.6 - Unauthenticated Arbitrary File Deletion
CM Download Manager < 2.9.1 - Cross-Site Request Forgery via editHeader
CM Download Manager < 2.9.0 - Cross-Site Request Forgery via delHeader
CM Download Manager < 2.9.0 - Cross-Site Request Forgery via unpublishHeader
CM Download Manager <= 2.8.5 - Authenticated (Administrator+) Arbitrary File Upload
CM Download Manager <= 2.7.0 - Cross-Site Scripting
CM Download Manager < 2.8.0 - Directory Traversal to Arbitrary File Deletion and Denial of Service
CM Download Manager <= 2.7.0 - Authenticated Stored Cross-Site Scripting
CM Download Manager <= 2.0.6 - Cross-Site Request Forgery to Cross-Site Scripting
CM Download Manager <= 2.0.3 - Code Injection
CM Download Manager – Organize, Protect & Share Files in WordPress Release Timeline
CM Download Manager – Organize, Protect & Share Files in WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CM Download Manager – Organize, Protect & Share Files in WordPress Attack Surface
AJAX Handlers 5
Shortcodes 4
WordPress Hooks 19
Maintenance & Trust
CM Download Manager – Organize, Protect & Share Files in WordPress Maintenance & Trust
Maintenance Signals
Community Trust
CM Download Manager – Organize, Protect & Share Files in WordPress Alternatives
Simple File List
simple-file-list
Simple File List gives your WordPress website a list of your files which allows your users to open and download them.
Shared Files – Frontend File Upload Form & Secure File Sharing
shared-files
File management plugin featuring frontend file upload form, download manager, statistics and download log.
File Sharing & Download Manager – User Private Files
user-private-files
Secure WordPress file sharing & download manager. Upload, manage & share private files with users safely.
Filr – Secure document library
filr-protection
Easily Create a Secure Document Library with Filr
Clinked Client Portal
clinked-client-portal
The Clinked Client Portal plugin is a great addition to the popular Clinked application - a branded, feature rich client portal.
CM Download Manager – Organize, Protect & Share Files in WordPress Developer Profile
19 plugins · 22K total installs
How We Detect CM Download Manager – Organize, Protect & Share Files in WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-download-manager/assets/css/animate.min.css/wp-content/plugins/cm-download-manager/assets/css/bootstrap.css/wp-content/plugins/cm-download-manager/assets/css/bootstrap-select.css/wp-content/plugins/cm-download-manager/assets/css/bootstrap-theme.css/wp-content/plugins/cm-download-manager/assets/css/bootstrap-theme.min.css/wp-content/plugins/cm-download-manager/assets/css/cm-download-manager-admin.css/wp-content/plugins/cm-download-manager/assets/css/cm-download-manager-public.css/wp-content/plugins/cm-download-manager/assets/css/cm-download-manager-public.min.css+31 more/wp-content/plugins/cm-download-manager/assets/js/jquery.js/wp-content/plugins/cm-download-manager/assets/js/jquery-ui.js/wp-content/plugins/cm-download-manager/assets/js/bootstrap.js/wp-content/plugins/cm-download-manager/assets/js/bootstrap-select.js/wp-content/plugins/cm-download-manager/assets/js/jquery.magnific-popup.js/wp-content/plugins/cm-download-manager/assets/js/jquery.Jcrop.js+5 moreHTML / DOM Fingerprints
cmdm-download-file-infocmdm-download-files-tablecmdm-download-file-blockcmdm-download-manager-pagecmdm-download-manager-wrapcmdm-download-manager-widgetcmdm-download-buttoncmdm-title+13 more<!-- CM Download Manager Start --><!-- CM Download Manager End --><!-- CMinds Free Package DM --><!-- CMinds Free Registration -->+3 moredata-cmdm-iddata-cmdm-pathdata-cmdm-namedata-cmdm-sizedata-cmdm-download-urldata-cminds-package-free-v1-1-5CMDMCMDM_SettingsCMDM_UtilsCMDM_AdminCMDM_PublicCMDM_Form+2 more[cminds_free_registration][cminds_free_guide][cminds_upgrade_box][cminds_free_activation]