Vulnerabilities > Wpchill > Download Monitor > 4.4.11

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2022-4972 Missing Authorization vulnerability in Wpchill Download Monitor
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51.
network
low complexity
wpchill CWE-862
7.5
2024-09-26 CVE-2024-8552 Missing Authorization vulnerability in Wpchill Download Monitor
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9.
network
low complexity
wpchill CWE-862
4.3
2024-03-29 CVE-2024-30501 Unspecified vulnerability in Wpchill Download Monitor
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
network
low complexity
wpchill
7.2
2024-01-08 CVE-2022-45354 Unspecified vulnerability in Wpchill Download Monitor
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
network
low complexity
wpchill
7.5
2023-12-20 CVE-2023-34007 Unspecified vulnerability in Wpchill Download Monitor
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
network
low complexity
wpchill
8.8
2023-11-13 CVE-2023-31219 Unspecified vulnerability in Wpchill Download Monitor
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.
network
low complexity
wpchill
4.9
2022-10-10 CVE-2022-2981 Unspecified vulnerability in Wpchill Download Monitor
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
network
low complexity
wpchill
4.9
2022-07-17 CVE-2022-2222 Unspecified vulnerability in Wpchill Download Monitor
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
network
low complexity
wpchill
4.9