CVE Database /
CVE-2022-4972
CVE · High
CVE-2022-4972 — Download Monitor [download-monitor] < 4.7.52
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-4972
|
Download Monitor [download-monitor] < 4.7.52 |
Missing Authorization |
High
7.5
|
< 4.7.52
|
4.7.52 |
2022-11-26 |
—
|
CVE-2022-4972
The Download Monitor plugin for WordPress contains an authorization bypass vulnerability in versions up to 4.7.51 where multiple REST API endpoints handling reporting functionality lack proper capability checks. This flaw allows unauthenticated attackers to access sensitive information including user data that should only be visible to administrators.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings