CVE · Medium

CVE-2022-2222 — Download Monitor [download-monitor] < 4.5.91

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2222 Download Monitor [download-monitor] < 4.5.91 Files or Directories Accessible to External Parties Medium 4.9 < 4.5.91 4.5.91 2022-06-27

CVE-2022-2222

The Download Monitor plugin for WordPress in version 4.5.9 and earlier contains an authenticated arbitrary file download vulnerability. A user with authentication credentials could exploit this flaw to download files without proper authorization restrictions. The vulnerability was patched in version 4.5.91 and administrators should upgrade to this version or later to secure their installations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.