First published: Sun Jul 17 2022(Updated: )
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPChill Download Monitor | <4.5.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2222 is a vulnerability in the Download Monitor WordPress plugin before version 4.5.91 that allows high privilege users to download sensitive files regardless of the security settings.
CVE-2022-2222 affects WordPress websites that are using the Download Monitor plugin before version 4.5.91.
The severity of CVE-2022-2222 is medium, with a severity value of 4.9.
To fix CVE-2022-2222, you should update the Download Monitor plugin to version 4.5.91 or later.
Yes, you can find more information about CVE-2022-2222 at this reference link: https://wpscan.com/vulnerability/dd48624a-1781-419c-a3c4-1e3eaf5e2c1b