CVE Database /
CVE-2022-2981
CVE · Medium
CVE-2022-2981 — Download Monitor [download-monitor] < 4.5.98
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-2981
|
Download Monitor [download-monitor] < 4.5.98 |
Files or Directories Accessible to External Parties |
Medium
4.9
|
< 4.5.98
|
4.5.98 |
2022-09-19 |
—
|
CVE-2022-2981
The Download Monitor plugin in versions up to 4.5.97 allows authenticated administrators and above to download any file from the server by bypassing directory validation checks. The plugin fails to confirm that requested files are located within the intended blog directory, enabling administrators to access arbitrary files on the affected WordPress installation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings