CVE · High

CVE-2022-4972 — Download Monitor [download-monitor] < 4.7.52

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4972 Download Monitor [download-monitor] < 4.7.52 Missing Authorization High 7.5 < 4.7.52 4.7.52 2022-11-26

CVE-2022-4972

The Download Monitor plugin for WordPress contains an authorization bypass vulnerability in versions up to 4.7.51 where multiple REST API endpoints handling reporting functionality lack proper capability checks. This flaw allows unauthenticated attackers to access sensitive information including user data that should only be visible to administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.