CVE-2025-47439
- EPSS 0.1%
- Veröffentlicht 07.05.2025 14:19:30
- Zuletzt bearbeitet 08.05.2025 14:39:18
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor allows PHP Local File Inclusion. This issue affects Download Monitor: from n/a through 5.0.22.
CVE-2024-10399
- EPSS 0.04%
- Veröffentlicht 30.10.2024 06:15:14
- Zuletzt bearbeitet 01.11.2024 12:57:03
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated at...
CVE-2024-10092
- EPSS 0.03%
- Veröffentlicht 26.10.2024 08:15:03
- Zuletzt bearbeitet 28.10.2024 13:58:09
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authen...
CVE-2022-4972
- EPSS 1.66%
- Veröffentlicht 16.10.2024 07:15:12
- Zuletzt bearbeitet 30.10.2024 16:34:55
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated att...
CVE-2024-8552
- EPSS 0.21%
- Veröffentlicht 26.09.2024 03:15:03
- Zuletzt bearbeitet 02.10.2024 17:00:45
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attacke...
CVE-2024-3269
- EPSS 0.14%
- Veröffentlicht 30.05.2024 04:15:10
- Zuletzt bearbeitet 21.11.2024 09:29:17
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authentica...
CVE-2024-30501
- EPSS 0.58%
- Veröffentlicht 29.03.2024 14:15:14
- Zuletzt bearbeitet 27.02.2025 14:53:37
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
CVE-2022-45354
- EPSS 88.32%
- Veröffentlicht 08.01.2024 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:29:05
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
CVE-2023-34007
- EPSS 0.31%
- Veröffentlicht 20.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:23
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
CVE-2023-31219
- EPSS 0.16%
- Veröffentlicht 13.11.2023 03:15:08
- Zuletzt bearbeitet 21.11.2024 08:01:38
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.