CVE · Medium

CVE-2024-10092 — Download Monitor [download-monitor] < 5.0.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10092 Download Monitor [download-monitor] < 5.0.13 Missing Authorization Medium 4.3 < 5.0.13 5.0.13 2024-10-25

CVE-2024-10092

The Download Monitor plugin through version 5.0.12 contains a flaw in the ajax_handle_api_key_actions function that fails to verify user permissions before processing requests. This oversight allows any authenticated user with subscriber-level privileges or higher to create new API keys and invalidate existing ones without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.