CVE · Critical

CVE-2023-34007 — Download Monitor [download-monitor] < 4.8.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-34007 Download Monitor [download-monitor] < 4.8.4 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 4.8.4 4.8.4 2023-06-07

CVE-2023-34007

The Download Monitor plugin for WordPress versions prior to 4.8.4 contains an arbitrary file upload vulnerability that was discovered by Nguyen Anh Tien. An attacker could exploit this flaw to upload files of any type to a WordPress site, potentially including malicious scripts that execute and provide unauthorized access to the website. This security issue has been patched in version 4.8.4 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.