CVE-2021-31567: WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerability
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadablefileurls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-31567?
CVE-2021-31567 is an Authenticated (admin+) Arbitrary File Download vulnerability discovered in the Download Monitor WordPress plugin.
What is the severity of CVE-2021-31567?
The severity of CVE-2021-31567 is medium with a CVSS score of 6.8.
How does CVE-2021-31567 affect the Download Monitor plugin?
CVE-2021-31567 affects Download Monitor plugin versions up to and including 4.4.6.
How can an attacker exploit CVE-2021-31567?
An attacker with admin+ privileges can exploit CVE-2021-31567 by downloading arbitrary files, including sensitive configuration files, using the &downloadable_file_urls[0] parameter in the plugin.
Is there a fix for CVE-2021-31567?
Yes, the vulnerability has been patched in Download Monitor plugin version 4.4.7 or higher.