CVE-2022-2981: Download Monitor < 4.5.98 - Admin+ Arbitrary File Download
Published Oct 10, 2022
·Updated
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
Affected Software
1 affected component
WPChill Download Monitor Wordpress<4.5.98
Event History
Oct 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2981.
2
What is the severity of CVE-2022-2981?
The severity of CVE-2022-2981 is medium (4.9).
3
What software is affected by CVE-2022-2981?
The Download Monitor WordPress plugin before version 4.5.98 is affected by CVE-2022-2981.
4
What is the impact of CVE-2022-2981?
The impact of CVE-2022-2981 is that high privilege users, such as admin, can download sensitive files like wp-config.php or /etc/passwd.
5
Is there a fix available for CVE-2022-2981?
Yes, updating to version 4.5.98 or higher of the Download Monitor WordPress plugin will fix CVE-2022-2981.