CVE-2022-4972
16.10.2024, 07:15
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.Enginsight
| Vendor | Product | Version |
|---|---|---|
| wpchill | download_monitor | 𝑥 ≤ 4.7.51 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References