Wpchill
Wpchill Download Monitor: vulnerabilidades y CVE
Wpchill Download Monitor tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-47439 | Alta (7.5) | 0.77% | — | 7 may 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects… |
| CVE-2022-4972 | Alta (7.5) | 0.47% | — | 16 oct 2024 | The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it… |
| CVE-2024-8552 | Media (4.3) | 0.37% | — | 26 sept 2024 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it… |
| CVE-2024-30501 | Alta (7.2) | 0.61% | — | 29 mar 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4. |
| CVE-2022-45354 | Alta (7.5) | 38% | — | 8 ene 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60. |
| CVE-2023-34007 | Alta (8.8) | 0.91% | — | 20 dic 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. |
| CVE-2023-31219 | Media (4.9) | 0.65% | — | 13 nov 2023 | Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1. |
| CVE-2022-2981 | Media (4.9) | 0.96% | — | 10 oct 2022 | The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php… |
| CVE-2022-2222 | Media (4.9) | 1.1% | — | 17 jul 2022 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php… |
| CVE-2021-31567 | Media (6.8) | 1.4% | — | 28 ene 2022 | Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as… |
| CVE-2021-23174 | Media (4.8) | 84% | — | 28 ene 2022 | Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0]. |
| CVE-2021-36920 | Media (5.4) | 0.57% | — | 14 ene 2022 | Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6). |
| CVE-2021-24786 | Alta (7.2) | 17% | — | 3 ene 2022 | The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.