Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.31% | — | Download MonitorAI | 2/10/2026 | 2/10/2026 | The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.30% | — | Download MonitorAI | 8/8/2026 | 26/8/2026 | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpforms Download MonitorAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | |
| Aplazada | Media (4.4) | 0.37% | — | Download MonitorAI | 15/6/2026 | 17/6/2026 | Author Arbitrary File Download in Download Monitor <= 5.1.9 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Download MonitorAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download Monitor: from n/a through <= 5.1.8. | |
| Aplazada | Media (5.4) | 0.19% | — | Download MonitorAI | 8/4/2026 | 24/7/2026 | The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.36% | — | Ironistic Download MonitorAI | 30/3/2026 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by… | |
| Aplazada | Media (6.4) | 0.20% | — | Simple Download MonitorAI | 27/2/2026 | 17/6/2026 | The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.32% | — | Simple Download MonitorAI | 28/8/2025 | 17/6/2026 | The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.17% | — | Mra13 Simple Download MonitorAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mra13 Simple Download Monitor simple-download-monitor allows Stored XSS.This issue affects Simple Download Monitor: from n/a through <= 3.9.34. | |
| Aplazada | Alta (7.5) | 0.80% | — | Wpchill Download MonitorAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22. | |
| Aplazada | Alta (7.6) | 0.58% | — | Simple Download MonitorAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mra13 Simple Download Monitor simple-download-monitor allows Blind SQL Injection.This issue affects Simple Download Monitor: from n/a through <= 3.9.25. | |
| Aplazada | Media (4.3) | 0.41% | — | Download MonitorAI | 30/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames… | |
| Aplazada | Media (4.3) | 0.45% | — | Ironikus Download MonitorAI | 26/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke… | |
| Analizada | Alta (7.5) | 0.47% | — | Wpchill Download Monitor | 16/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for… | |
| Analizada | Media (4.3) | 0.37% | — | Wpchill Download Monitor | 26/9/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop… | |
| Aplazada | Media (5.4) | 0.30% | — | Download MonitorAI | 30/5/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data. | |
| Modificada | Alta (7.2) | 0.61% | — | Wpchill Download Monitor | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4. | |
| Modificada | Alta (7.5) | 38% | — | Wpchill Download Monitor | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60. | |
| Modificada | Alta (8.8) | 0.91% | — | Wpchill Download Monitor | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. | |
| Modificada | Media (4.9) | 0.65% | — | Wpchill Download Monitor | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1. | |
| Modificada | Media (4.9) | 0.96% | — | Wpchill Download Monitor | 10/10/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup. | |
| Modificada | Media (4.9) | 1.1% | — | Wpchill Download Monitor | 17/7/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup. | |
| Modificada | Media (6.5) | 1.4% | — | Tipsandtricks-hq Simple Download Monitor | 14/3/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector. | |
| Modificada | Media (6.8) | 1.4% | — | Wpchill Download Monitor | 28/1/2022 | 17/6/2026 | Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to… |