CVE · Medium

CVE-2021-23174 — Download Monitor [download-monitor] < 4.4.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-23174 Download Monitor [download-monitor] < 4.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.4.7 4.4.7 2021-10-29

CVE-2021-23174

The Download Monitor WordPress plugin through version 4.4.6 contains an authenticated persistent cross-site scripting vulnerability accessible to users with administrative privileges. The flaw exists in the post_title parameter and the downloadable_file_version[0] field, which fail to properly sanitize user input. An attacker with admin access could inject malicious scripts that would be stored and executed for other users visiting the affected pages. The vulnerability was patched in version 4.4.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.