CVE-2022-2222: Download Monitor < 4.5.91 - Admin+ Arbitrary File Download
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2222?
CVE-2022-2222 is a vulnerability in the Download Monitor WordPress plugin before version 4.5.91 that allows high privilege users to download sensitive files regardless of the security settings.
How does CVE-2022-2222 affect WordPress websites?
CVE-2022-2222 affects WordPress websites that are using the Download Monitor plugin before version 4.5.91.
What is the severity of CVE-2022-2222?
The severity of CVE-2022-2222 is medium, with a severity value of 4.9.
How can I fix CVE-2022-2222?
To fix CVE-2022-2222, you should update the Download Monitor plugin to version 4.5.91 or later.
Is there any additional information available about CVE-2022-2222?
Yes, you can find more information about CVE-2022-2222 at this reference link: https://wpscan.com/vulnerability/dd48624a-1781-419c-a3c4-1e3eaf5e2c1b