CVE Database /
CVE-2024-10092
CVE · Medium
CVE-2024-10092 — Download Monitor [download-monitor] < 5.0.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10092
|
Download Monitor [download-monitor] < 5.0.13 |
Missing Authorization |
Medium
4.3
|
< 5.0.13
|
5.0.13 |
2024-10-25 |
—
|
CVE-2024-10092
The Download Monitor plugin through version 5.0.12 contains a flaw in the ajax_handle_api_key_actions function that fails to verify user permissions before processing requests. This oversight allows any authenticated user with subscriber-level privileges or higher to create new API keys and invalidate existing ones without proper authorization.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings