CVE Database /
CVE-2021-23174
CVE · Medium
CVE-2021-23174 — Download Monitor [download-monitor] < 4.4.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-23174
|
Download Monitor [download-monitor] < 4.4.7 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 4.4.7
|
4.4.7 |
2021-10-29 |
—
|
CVE-2021-23174
The Download Monitor WordPress plugin through version 4.4.6 contains an authenticated persistent cross-site scripting vulnerability accessible to users with administrative privileges. The flaw exists in the post_title parameter and the downloadable_file_version[0] field, which fail to properly sanitize user input. An attacker with admin access could inject malicious scripts that would be stored and executed for other users visiting the affected pages. The vulnerability was patched in version 4.4.7.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings