CVE · Medium

CVE-2022-2981 — Download Monitor [download-monitor] < 4.5.98

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2981 Download Monitor [download-monitor] < 4.5.98 Files or Directories Accessible to External Parties Medium 4.9 < 4.5.98 4.5.98 2022-09-19

CVE-2022-2981

The Download Monitor plugin in versions up to 4.5.97 allows authenticated administrators and above to download any file from the server by bypassing directory validation checks. The plugin fails to confirm that requested files are located within the intended blog directory, enabling administrators to access arbitrary files on the affected WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.