Download Monitor <= 5.2.5 - Missing Authorization
medium
The Download Monitor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Aug 3, 2026
CVE-2026-16608 on NVD →
Download Monitor <= 5.1.9 - Authenticated (Author+) Arbitrary File Download
medium
The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.9. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 4.3
- Affected:
- up to 5.1.9
- Fixed in:
- 5.1.10
- Disclosed:
- Apr 20, 2026
CVE-2026-39489 on NVD →
Download Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and Disabling
medium
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for u...
- CVSS:
- 5.4
- Affected:
- up to 5.1.10
- Fixed in:
- 5.1.11
- Disclosed:
- Apr 7, 2026
CVE-2026-4401 on NVD →
Download Monitor - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability
medium
Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' vulnerability
- CVSS:
- 5.3
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.8
- Disclosed:
- Mar 30, 2026
Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id'
high
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by explo...
- CVSS:
- 7.5
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.8
- Disclosed:
- Mar 29, 2026
CVE-2026-3124 on NVD →
Download Monitor <= 5.1.8 - Authenticated (Contributor+) SQL Injection
medium
The Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 6.5
- Affected:
- up to 5.1.8
- Fixed in:
- 5.1.9
- Disclosed:
- Mar 25, 2026
CVE-2026-39486 on NVD →
Download Monitor <= 5.0.22 - Authenticated (Contributor+) Local File Inclusion
high
The Download Monitor plugin for WordPress is vulnerable to Local File Inclusion via the get_template_part() function in versions up to, and including, 5.0.22. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the e...
- CVSS:
- 8.8
- Affected:
- up to 5.0.22
- Fixed in:
- 5.0.23
- Disclosed:
- May 7, 2025
CVE-2025-47439 on NVD →
Download Monitor [download-monitor] < 5.0.23
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor allows PHP Local File Inclusion. This issue affects Download Monitor: from n/a through 5.0.22.
- Affected:
- up to 5.0.23
- Fixed in:
- 5.0.23
- Disclosed:
- May 7, 2025
CVE-2025-47439 on NVD →
Download Monitor [download-monitor] < 5.0.14
unknown
[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain userna...
- Affected:
- up to 5.0.14
- Fixed in:
- 5.0.14
- Disclosed:
- Oct 30, 2024
CVE-2024-10399 on NVD →
Download Monitor <= 5.0.13 - Missing Authorization to Sensitive Information Exposure
medium
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames a...
- CVSS:
- 4.3
- Affected:
- up to 5.0.13
- Fixed in:
- 5.0.14
- Disclosed:
- Oct 29, 2024
CVE-2024-10399 on NVD →
Download Monitor [download-monitor] < 5.0.13
unknown
[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to rev...
- Affected:
- up to 5.0.13
- Fixed in:
- 5.0.13
- Disclosed:
- Oct 26, 2024
CVE-2024-10092 on NVD →
Download Monitor <= 5.0.12 - Missing Authorization to API Key Manipulation
medium
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke e...
- CVSS:
- 4.3
- Affected:
- up to 5.0.12
- Fixed in:
- 5.0.13
- Disclosed:
- Oct 25, 2024
CVE-2024-10092 on NVD →
Download Monitor [download-monitor] < 4.7.52
unknown
[en] The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended...
- Affected:
- up to 4.7.52
- Fixed in:
- 4.7.52
- Disclosed:
- Oct 16, 2024
CVE-2022-4972 on NVD →
Download Monitor [download-monitor] < 5.0.10
unknown
[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop functi...
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.10
- Disclosed:
- Sep 26, 2024
CVE-2024-8552 on NVD →
Download Monitor <= 5.0.9 - Missing Authorization to Authenticated (Subscriber+) Shop Enable
medium
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop functionali...
- CVSS:
- 4.3
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.10
- Disclosed:
- Sep 25, 2024
CVE-2024-8552 on NVD →
Download Monitor [download-monitor] < 4.9.14
unknown
[en] The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.
- Affected:
- up to 4.9.14
- Fixed in:
- 4.9.14
- Disclosed:
- May 30, 2024
CVE-2024-3269 on NVD →
Download Monitor <= 4.9.13 - Missing Authorization
medium
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.
- CVSS:
- 5.4
- Affected:
- up to 4.9.13
- Fixed in:
- 4.9.14
- Disclosed:
- May 29, 2024
CVE-2024-3269 on NVD →
Download Monitor [download-monitor] < 4.9.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.5
- Disclosed:
- Mar 29, 2024
CVE-2024-30501 on NVD →
Download Monitor <= 4.9.4 - Authenticated (Admin+) SQL Injection
high
The Download Monitor plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter in all versions up to 4.9.5 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with a...
- CVSS:
- 7.2
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.5
- Disclosed:
- Jan 8, 2024
CVE-2024-30501 on NVD →
Download Monitor [download-monitor] < 4.9.5
unknown
Update the WordPress Download Monitor plugin to the latest available version (at least 4.9.5).
WordFence discovered and reported this SQL Injection vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing inform...
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.5
- Disclosed:
- Jan 8, 2024
Download Monitor [download-monitor] < 4.9.5
unknown
The Download Monitor plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter in all versions up to 4.9.5 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with a...
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.5
- Disclosed:
- Jan 8, 2024
Download Monitor [download-monitor] < 4.7.70
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
- Affected:
- up to 4.7.70
- Fixed in:
- 4.7.70
- Disclosed:
- Jan 8, 2024
CVE-2022-45354 on NVD →
Download Monitor [download-monitor] < 4.8.4
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.4
- Disclosed:
- Dec 20, 2023
CVE-2023-34007 on NVD →
Download Monitor [download-monitor] < 4.8.2
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.
- Affected:
- up to 4.8.2
- Fixed in:
- 4.8.2
- Disclosed:
- Nov 13, 2023
CVE-2023-31219 on NVD →
Download Monitor [download-monitor] < 4.7.70
unknown
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.60. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to view use...
- Affected:
- up to 4.7.70
- Fixed in:
- 4.7.70
- Disclosed:
- Jun 9, 2023
Download Monitor <= 4.8.3 - Authenticated(Subscriber+) Arbitrary File Upload via upload_file
high
The Download Monitor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and access controls on the 'upload_file' function in versions up to, and including, 4.8.3. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitr...
- CVSS:
- 8.8
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.4
- Disclosed:
- Jun 7, 2023
CVE-2023-34007 on NVD →
Download Monitor [download-monitor] < 4.8.4
unknown
The Download Monitor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and access controls on the 'upload_file' function in versions up to, and including, 4.8.3. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitr...
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.4
- Disclosed:
- Jun 7, 2023
Download Monitor <= 4.8.1 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Download Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 4.8.1 via the trigger() function. This makes it possible for authenticated attackers with administrative privileges to make web requests to arbitrary locations originating from the web application an...
- CVSS:
- 5.5
- Affected:
- up to 4.8.1
- Fixed in:
- 4.8.2
- Disclosed:
- May 30, 2023
CVE-2023-31219 on NVD →
Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API
medium
The Download Monitor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.7.60 via REST API. This can allow unauthenticated attackers to extract sensitive data including user reports, download reports, and user data including email, role, id and other info (not passwo...
- CVSS:
- 5.4
- Affected:
- up to 4.7.60
- Fixed in:
- 4.7.70
- Disclosed:
- May 10, 2023
CVE-2022-45354 on NVD →
Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export
high
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for...
- CVSS:
- 7.5
- Affected:
- up to 4.7.51
- Fixed in:
- 4.7.52
- Disclosed:
- Nov 26, 2022
CVE-2022-4972 on NVD →
Download Monitor [download-monitor] < 4.7.52
unknown
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for...
- Affected:
- up to 4.7.52
- Fixed in:
- 4.7.52
- Disclosed:
- Nov 26, 2022
Download Monitor <= 4.7.2 - Authenticated Directory Traversal to Sensitive Information Exposure
medium
The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.7.2 via the list_files function. This allows users with manage_downloads permissions to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 4.9
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.3
- Disclosed:
- Nov 1, 2022
Download Monitor [download-monitor] < 4.7.3
unknown
The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.7.2 via the list_files function. This allows users with manage_downloads permissions to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected:
- up to 4.7.3
- Fixed in:
- 4.7.3
- Disclosed:
- Nov 1, 2022
Download Monitor [download-monitor] < 4.5.98
unknown
[en] The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
- Affected:
- up to 4.5.98
- Fixed in:
- 4.5.98
- Disclosed:
- Oct 10, 2022
CVE-2022-2981 on NVD →
Download Monitor <= 4.5.97 - Authenticated (Administrator+) Arbitrary File Download
medium
The Download Monitor plugin for WordPress is vulnerable to arbitrary file downloads due to not verifying that downloaded files reside within the blog directory in versions up to, and including, 4.5.97. This makes it possible for authenticated attackers, with administrator-level permissions and above, to download arbitr...
- CVSS:
- 6.8
- Affected:
- up to 4.5.97
- Fixed in:
- 4.5.98
- Disclosed:
- Sep 19, 2022
CVE-2022-2981 on NVD →
Download Monitor [download-monitor] < 4.5.91
unknown
[en] The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
- Affected:
- up to 4.5.91
- Fixed in:
- 4.5.91
- Disclosed:
- Jul 17, 2022
CVE-2022-2222 on NVD →
Download Monitor <= 4.5.9 - Authenticated Arbitrary File Download
medium
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
- CVSS:
- 4.9
- Affected:
- up to 4.5.9
- Fixed in:
- 4.5.91
- Disclosed:
- Jun 27, 2022
CVE-2022-2222 on NVD →
Download Monitor [download-monitor] < 4.4.7
unknown
[en] Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- Jan 28, 2022
CVE-2021-23174 on NVD →
Download Monitor [download-monitor] < 4.4.7
unknown
[en] Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible...
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- Jan 28, 2022
CVE-2021-31567 on NVD →
Download Monitor [download-monitor] < 4.4.7
unknown
[en] Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- Jan 14, 2022
CVE-2021-36920 on NVD →
Download Monitor [download-monitor] < 4.4.5
unknown
[en] The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
- Affected:
- up to 4.4.5
- Fixed in:
- 4.4.5
- Disclosed:
- Jan 3, 2022
CVE-2021-24786 on NVD →
Download Monitor <= 4.4.6 - Authenticated (Admin+) Arbitrary File Download
medium
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to es...
- CVSS:
- 6.8
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Oct 29, 2021
CVE-2021-31567 on NVD →
Download Monitor <= 4.4.6 - Reflected Cross-Site Scripting
medium
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
- CVSS:
- 6.1
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Oct 29, 2021
CVE-2021-36920 on NVD →
Download Monitor <= 4.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
- CVSS:
- 5.5
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Oct 29, 2021
CVE-2021-23174 on NVD →
Download Monitor <= 4.4.4 - Admin+ SQL Injection via orderby parameter
high
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
- CVSS:
- 7.2
- Affected:
- up to 4.4.5
- Fixed in:
- 4.4.5
- Disclosed:
- Oct 20, 2021
CVE-2021-24786 on NVD →
Download Monitor [download-monitor] < 1.7.1
unknown
[en] The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Aug 13, 2019
CVE-2015-9296 on NVD →
Download Monitor <= 1.9.6 - Missing Authorization
medium
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the delete_logs() and export_logs() functions in versions up to, and including, 1.9.6. This makes it possible for unauthenticated attackers to delete and export several log types.
- CVSS:
- 6.5
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.7
- Disclosed:
- May 5, 2017
Download Monitor [download-monitor] < 1.9.7
unknown
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the delete_logs() and export_logs() functions in versions up to, and including, 1.9.6. This makes it possible for unauthenticated attackers to delete and export several log types.
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7
- Disclosed:
- May 5, 2017
Download Monitor [download-monitor] < 1.6.4
unknown
This plugin is prone to an authenticated directory listing vulnerability. It allows attackers list sever side files and directories.
Update the plugin.
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Aug 11, 2016
Download Monitor [download-monitor] < 1.7.1
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- May 15, 2015
Download Monitor <= 1.6.4 - Reflected Cross-Site Scripting
medium
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...
- CVSS:
- 6.1
- Affected:
- up to 1.6.5, 1.7.0 – 1.7.0
- Fixed in:
- 1.6.5
- Disclosed:
- Apr 20, 2015
Download Monitor < 1.7.1 - Reflected Cross-Site Scripting
medium
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
- CVSS:
- 6.1
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Apr 20, 2015
CVE-2015-9296 on NVD →
Download Monitor [download-monitor] <= 1.6.4
unknown
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browse...
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Apr 20, 2015
Download Monitor <= 1.6.3 - Directory Listing to Information Disclosure
medium
The Download Monitor plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.6.3 via the 'dir' parameter. This can allow authenticated attackers to extract sensitive data including directories and otherwise restricted server-side filenames.
- CVSS:
- 5.3
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Mar 8, 2015
Download Monitor [download-monitor] < 1.6.4
unknown
The Download Monitor plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.6.3 via the 'dir' parameter. This can allow authenticated attackers to extract sensitive data including directories and otherwise restricted server-side filenames.
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Mar 8, 2015
Download Monitor [download-monitor] < 3.3.5.9
unknown
[en] Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
- Affected:
- up to 3.3.5.9
- Fixed in:
- 3.3.5.9
- Disclosed:
- Sep 4, 2014
CVE-2012-4768 on NVD →
Download Monitor [download-monitor] < 3.3.6.2
unknown
[en] Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.
- Affected:
- up to 3.3.6.2
- Fixed in:
- 3.3.6.2
- Disclosed:
- Aug 9, 2013
CVE-2013-3262 on NVD →
Download Monitor [download-monitor] < 3.3.6.2
unknown
[en] Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
- Affected:
- up to 3.3.6.2
- Fixed in:
- 3.3.6.2
- Disclosed:
- Aug 9, 2013
CVE-2013-5098 on NVD →
Download Monitor < 3.3.6.2 - Cross-Site Scripting via sort Parameter
high
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
- CVSS:
- 7.2
- Affected:
- up to 3.3.6.2
- Fixed in:
- 3.3.6.2
- Disclosed:
- Jul 23, 2013
CVE-2013-5098 on NVD →
Download Monitor < 3.3.6.2 - Cross-Site Scripting via p Parameter
medium
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.
- CVSS:
- 6.1
- Affected:
- up to 3.3.6.2
- Fixed in:
- 3.3.6.2
- Disclosed:
- Jul 22, 2013
CVE-2013-3262 on NVD →
Download Monitor <= 3.3.5.8 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
- CVSS:
- 6.1
- Affected:
- up to 3.3.5.8
- Fixed in:
- 3.3.5.9
- Disclosed:
- Sep 6, 2012
CVE-2012-4768 on NVD →
Download Monitor [download-monitor] < 2.0.9
unknown
[en] SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Apr 30, 2008
CVE-2008-2034 on NVD →
Download Monitor <= 2.0.6 - Unauthenticated SQL Injection
critical
SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVSS:
- 9.8
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.9
- Disclosed:
- Apr 28, 2008
CVE-2008-2034 on NVD →
Download Monitor [download-monitor] < 1.2.1
unknown
[en] SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Apr 2, 2008
CVE-2008-1646 on NVD →
Download Monitor [download-monitor] < 1.6.4
unknown
Directory listing vulnerability that can lead to information disclosure. Authenticated users can list sever side files and directories.
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
Download Monitor [download-monitor] < 1.9.7
unknown
An Unauthenticated attacker can export download logs from the Plugin. Which includes: Download ID, Version ID, Filename, User ID, User Login, User Email, User IP, User Agent, Date, Status.
The information could potentially be used to mount further attacks or just collect contact information.
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.7