CVE-2021-36920: WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36920?
The severity of CVE-2021-36920 is medium with a severity value of 5.4.
Which software is affected by CVE-2021-36920?
The WordPress plugin Download Monitor (versions <= 4.4.6) is affected by CVE-2021-36920.
What is the vulnerability type of CVE-2021-36920?
CVE-2021-36920 is an Authenticated Reflected Cross-Site Scripting (XSS) vulnerability.
How can I fix CVE-2021-36920?
To fix CVE-2021-36920, upgrade the affected version of the Download Monitor plugin to a version above 4.4.6.
Where can I find more information about CVE-2021-36920?
You can find more information about CVE-2021-36920 in the references: [Reference 1](https://patchstack.com/database/vulnerability/download-monitor/wordpress-download-monitor-plugin-4-4-6-authenticated-reflected-cross-site-scripting-xss-vulnerability), [Reference 2](https://wordpress.org/plugins/download-monitor/#developers).