CVE · Medium

CVE-2021-31567 — Download Monitor [download-monitor] < 4.4.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-31567 Download Monitor [download-monitor] < 4.4.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.8 < 4.4.7 4.4.7 2021-10-29

CVE-2021-31567

Download Monitor versions 4.4.6 and earlier contain an authenticated arbitrary file download vulnerability that affects users with admin privileges. An authenticated administrator can exploit the downloadable_file_urls[0] parameter to download sensitive files from the server, such as wp-config.php, or access files outside the web root directory by traversing the file system. This flaw allows unrestricted access to arbitrary files on the operating system where the WordPress installation resides. The vulnerability has been addressed in version 4.4.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.