NA

CVE-2022-2981

Published: 10/10/2022 Updated: 12/10/2022
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The Download Monitor WordPress plugin prior to 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpchill download monitor