Download Monitor <= 4.5.9 - Authenticated Arbitrary File Download

2022-06-27 00:00
Thiago Martins

Strategic Overview

Status
Patched in 4.5.91
Affected PluginDownload Monitor
Affected Version<= 4.5.9
CVSS4.9Medium
CVECVE-2022-2222
View all Download Monitor vulnerabilities

Vulnerability Overview

The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

Technical Analysis

REMEDIATION: Update to version 4.5.91, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C