+ 31 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-30501
|
Download Monitor [download-monitor] < 4.9.5 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,2
|
< 4.9.5
|
4.9.5 |
2024-03-29 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 4.9.5 |
— |
Desconocido
|
< 4.9.5
|
4.9.5 |
2024-01-08 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 4.9.5 |
— |
Desconocido
|
< 4.9.5
|
4.9.5 |
2024-01-08 |
✓ corregido en la última versión
|
|
CVE-2023-34007
|
Download Monitor [download-monitor] < 4.8.4 |
Carga de archivos sin restricción de tipo peligroso |
Crítica
9,9
|
< 4.8.4
|
4.8.4 |
2023-06-13 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 4.7.70 |
— |
Desconocido
|
< 4.7.70
|
4.7.70 |
2023-06-09 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 4.8.4 |
— |
Desconocido
|
< 4.8.4
|
4.8.4 |
2023-06-07 |
✓ corregido en la última versión
|
|
CVE-2023-31219
|
Download Monitor [download-monitor] < 4.8.2 |
Falsificación de petición del lado del servidor (SSRF) |
Media
4,1
|
< 4.8.2
|
4.8.2 |
2023-05-30 |
✓ corregido en la última versión
|
|
CVE-2022-45354
|
Download Monitor [download-monitor] < 4.7.70 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 4.7.70
|
4.7.70 |
2023-05-10 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 4.7.52 |
— |
Desconocido
|
< 4.7.52
|
4.7.52 |
2022-11-26 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 4.7.3 |
— |
Desconocido
|
< 4.7.3
|
4.7.3 |
2022-11-01 |
✓ corregido en la última versión
|
|
CVE-2022-2981
|
Download Monitor [download-monitor] < 4.5.98 |
Archivos o directorios accesibles a terceros |
Media
4,9
|
< 4.5.98
|
4.5.98 |
2022-09-19 |
✓ corregido en la última versión
|
|
CVE-2022-2222
|
Download Monitor [download-monitor] < 4.5.91 |
Archivos o directorios accesibles a terceros |
Media
4,9
|
< 4.5.91
|
4.5.91 |
2022-06-27 |
✓ corregido en la última versión
|
|
CVE-2021-23174
|
Download Monitor [download-monitor] < 4.4.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 4.4.7
|
4.4.7 |
2021-10-29 |
✓ corregido en la última versión
|
|
CVE-2021-31567
|
Download Monitor [download-monitor] < 4.4.7 |
Exposición de información sensible a un actor no autorizado |
Media
6,8
|
< 4.4.7
|
4.4.7 |
2021-10-29 |
✓ corregido en la última versión
|
|
CVE-2021-36920
|
Download Monitor [download-monitor] < 4.4.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 4.4.7
|
4.4.7 |
2021-10-29 |
✓ corregido en la última versión
|
|
CVE-2021-24786
|
Download Monitor [download-monitor] < 4.4.5 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,2
|
< 4.4.5
|
4.4.5 |
2021-10-20 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 1.9.7 |
— |
Desconocido
|
< 1.9.7
|
1.9.7 |
2017-05-05 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 1.6.4 |
— |
Desconocido
|
< 1.6.4
|
1.6.4 |
2016-08-11 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 1.7.1 |
— |
Desconocido
|
< 1.7.1
|
1.7.1 |
2015-05-15 |
✓ corregido en la última versión
|
|
CVE-2015-9296
|
Download Monitor [download-monitor] < 1.7.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.7.1
|
1.7.1 |
2015-04-20 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] <= 1.6.4 |
— |
Desconocido
|
< 1.6.4
|
1.6.4 |
2015-04-20 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 1.6.4 |
— |
Desconocido
|
< 1.6.4
|
1.6.4 |
2015-03-08 |
✓ corregido en la última versión
|
|
CVE-2013-5098
|
Download Monitor [download-monitor] < 3.3.6.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 3.3.6.2
|
3.3.6.2 |
2013-07-23 |
✓ corregido en la última versión
|
|
CVE-2013-3262
|
Download Monitor [download-monitor] < 3.3.6.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 3.3.6.2
|
3.3.6.2 |
2013-04-22 |
✓ corregido en la última versión
|
|
CVE-2012-4768
|
Download Monitor [download-monitor] < 3.3.5.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 3.3.5.9
|
3.3.5.9 |
2012-08-30 |
✓ corregido en la última versión
|
|
CVE-2008-2034
|
Download Monitor [download-monitor] < 2.0.9 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Desconocido
|
< 2.0.9
|
2.0.9 |
2008-04-28 |
✓ corregido en la última versión
|
|
CVE-2008-1646
|
Download Monitor [download-monitor] < 1.2.1 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Desconocido
|
< 1.2.1
|
1.2.1 |
2008-03-31 |
✓ corregido en la última versión
|
|
CVE-2026-3124
|
Download Monitor [download-monitor] < 5.1.8 |
— |
Desconocido
|
< 5.1.8
|
5.1.8 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-4401
|
Download Monitor [download-monitor] < 5.1.11 |
— |
Media
5,4
|
< 5.1.11
|
5.1.11 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 1.9.7 |
— |
Desconocido
|
< 1.9.7
|
1.9.7 |
— |
✓ corregido en la última versión
|
|
—
|
Download Monitor [download-monitor] < 1.6.4 |
— |
Desconocido
|
< 1.6.4
|
1.6.4 |
— |
✓ corregido en la última versión
|
CVE-2024-30501
Update the WordPress Download Monitor plugin to the latest available version (at least 4.9.5).
movrment discovered and reported this SQL Injection vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 4.9.5.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Download Monitor [download-monitor] < 4.9.5
The Download Monitor plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter in all versions up to 4.9.5 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Download Monitor [download-monitor] < 4.9.5
Update the WordPress Download Monitor plugin to the latest available version (at least 4.9.5).
WordFence discovered and reported this SQL Injection vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 4.9.5.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-34007
Update the WordPress Download Monitor plugin to the latest available version (at least 4.8.4).
Nguyen Anh Tien discovered and reported this Arbitrary File Upload vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 4.8.4.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Download Monitor [download-monitor] < 4.7.70
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.60. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to view user data and other sensitive information intended for administrators.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Download Monitor [download-monitor] < 4.8.4
The Download Monitor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and access controls on the 'upload_file' function in versions up to, and including, 4.8.3. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-31219
Update the WordPress Download Monitor plugin to the latest available version (at least 4.8.2).
Mika discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 4.8.2.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-45354
The Download Monitor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.7.60 via REST API. This can allow unauthenticated attackers to extract sensitive data including user reports, download reports, and user data including email, role, id and other info (not passwords)
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Download Monitor [download-monitor] < 4.7.52
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Download Monitor [download-monitor] < 4.7.3
The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.7.2 via the list_files function. This allows users with manage_downloads permissions to read the contents of arbitrary files on the server, which can contain sensitive information.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-2981
The Download Monitor plugin for WordPress is vulnerable to arbitrary file downloads due to not verifying that downloaded files reside within the blog directory in versions up to, and including, 4.5.97. This makes it possible for authenticated attackers, with administrator-level permissions and above, to download arbitrary files on the affected site's server.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-2222
Authenticated Arbitrary File Download vulnerability discovered by Thiago Martins, Jorge Buzeti, Leandro Inacio, Lucas de Souza, Matheus Oliveira, Filipe Baptistella, Leonardo Paiva, Jose Thomaz, Joao Maciel, Vinicius Pereira, Geovanni Campos, Hudson Nowak, Guilherme Acerbi in WordPress Download Monitor plugin (versions <= 4.5.9).
Update the WordPress Download Monitor plugin to the latest available version (at least 4.5.91).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-23174
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-31567
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-36920
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Nguy Minh Tuan in WordPress Download Monitor plugin (versions <= 4.4.6).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-24786
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Download Monitor [download-monitor] < 1.9.7
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the delete_logs() and export_logs() functions in versions up to, and including, 1.9.6. This makes it possible for unauthenticated attackers to delete and export several log types.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Download Monitor [download-monitor] < 1.6.4
This plugin is prone to an authenticated directory listing vulnerability. It allows attackers list sever side files and directories.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Download Monitor [download-monitor] < 1.7.1
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2015-9296
The Download Monitor WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Download Monitor [download-monitor] <= 1.6.4
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Download Monitor [download-monitor] < 1.6.4
The Download Monitor plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.6.3 via the 'dir' parameter. This can allow authenticated attackers to extract sensitive data including directories and otherwise restricted server-side filenames.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2013-5098
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2013-3262
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2012-4768
WordPress Download Monitor plugin's "dlsearch" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials. Other attacks are also possible.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2008-2034
SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2008-1646
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-3124
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between the PayPal transaction token and the local order, allowing theft of paid digital goods by paying a minimal amount for a low-cost item and using that payment token to finalize a high-value order.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-4401
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for unauthenticated attackers to delete, disable, or enable approved download paths via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Download Monitor [download-monitor] < 1.9.7
An Unauthenticated attacker can export download logs from the Plugin. Which includes: Download ID, Version ID, Filename, User ID, User Login, User Email, User IP, User Agent, Date, Status.
The information could potentially be used to mount further attacks or just collect contact information.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Download Monitor [download-monitor] < 1.6.4
Directory listing vulnerability that can lead to information disclosure. Authenticated users can list sever side files and directories.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Mantén Download Monitor actualizado — 5.2.5 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.