First published: Fri Jan 28 2022(Updated: )
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPChill Download Monitor | <4.4.7 |
Update to 4.4.7 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23174 is an authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in the Download Monitor WordPress plugin (versions <= 4.4.6).
CVE-2021-23174 has a severity score of 4.8, which is considered medium.
The Download Monitor WordPress plugin versions up to and including 4.4.6 are affected by CVE-2021-23174.
The vulnerable parameters in CVE-2021-23174 are &post_title and &downloadable_file_version[0].
Yes, a patch for CVE-2021-23174 is available. Reference: [link]