CVE-2021-23174: WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Published Jan 28, 2022
·Updated
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &posttitle, &downloadablefileversion[0].
Affected Software
1 affected component
WPChill Download Monitor Wordpress<4.4.7
Remediation
Information
Update to 4.4.7 or higher version.
Event History
Jan 28, 2022
CVE Published
via MITRE·07:09 PM
Data Sourced
via MITRE·07:09 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-23174?
CVE-2021-23174 is an authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in the Download Monitor WordPress plugin (versions <= 4.4.6).
2
How severe is CVE-2021-23174?
CVE-2021-23174 has a severity score of 4.8, which is considered medium.
3
What software is affected by CVE-2021-23174?
The Download Monitor WordPress plugin versions up to and including 4.4.6 are affected by CVE-2021-23174.
4
What is the vulnerable parameter in CVE-2021-23174?
The vulnerable parameters in CVE-2021-23174 are &post_title and &downloadable_file_version[0].
5
Is there a patch or fix available for CVE-2021-23174?
Yes, a patch for CVE-2021-23174 is available. Reference: [link]