CVE · Medium

CVE-2024-8552 — Download Monitor [download-monitor] < 5.0.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8552 Download Monitor [download-monitor] < 5.0.10 Missing Authorization Medium 4.3 < 5.0.10 5.0.10 2024-09-25

CVE-2024-8552

Authenticated users with at least Subscriber-level permissions can modify plugin settings due to an oversight in capability checks on the enable_shop function within Download Monitor, affecting all versions up to 5.0.9. This vulnerability allows them to activate shop features without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.