📦

download_monitor

Vendor: wpchill

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 16 Total Indexed
Avg. EPSS 12.18% Exploit Prob.
Latest CVE CVE-2022-4972 Oct 16

Security Vulnerability Index

Page 2 / 2
4.8 CVSS

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).

EPSS: 0.57%
7.2 CVSS
CVE-2021-24786
Exploit Found

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

EPSS: 17.35%