Vulnerabilities > Wpchill > Download Monitor > 1.6.1

DATE CVE VULNERABILITY TITLE RISK
2022-01-14 CVE-2021-36920 Cross-site Scripting vulnerability in Wpchill Download Monitor
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
network
low complexity
wpchill CWE-79
5.4
2022-01-03 CVE-2021-24786 SQL Injection vulnerability in Wpchill Download Monitor
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
network
low complexity
wpchill CWE-89
7.2