Vulnerabilities > Wpchill > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2022-4972 Missing Authorization vulnerability in Wpchill Download Monitor
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51.
network
low complexity
wpchill CWE-862
7.5
2024-01-08 CVE-2022-45354 Unspecified vulnerability in Wpchill Download Monitor
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
network
low complexity
wpchill
7.5
2024-01-05 CVE-2023-52123 Cross-Site Request Forgery (CSRF) vulnerability in Wpchill Strong Testimonials
Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.
network
low complexity
wpchill CWE-352
8.8
2023-12-20 CVE-2023-34007 Unrestricted Upload of File with Dangerous Type vulnerability in Wpchill Download Monitor
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
network
low complexity
wpchill CWE-434
8.8