First published: Mon Jan 08 2024(Updated: )
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPChill Download Monitor | <=4.7.60 |
Update to 4.7.70 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45354 is classified as a high-severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2022-45354, update the WPChill Download Monitor plugin to the latest version beyond 4.7.60, where the vulnerability has been addressed.
CVE-2022-45354 affects all users of the Download Monitor plugin for WordPress versions up to and including 4.7.60.
CVE-2022-45354 may allow unauthorized actors to access sensitive information stored by the Download Monitor plugin.
The recommended action for CVE-2022-45354 is to upgrade the plugin, as no effective workaround is provided for mitigating the vulnerability.