CVE-2022-45354: WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45354?
CVE-2022-45354 is classified as a high-severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2022-45354?
To fix CVE-2022-45354, update the WPChill Download Monitor plugin to the latest version beyond 4.7.60, where the vulnerability has been addressed.
Who is affected by CVE-2022-45354?
CVE-2022-45354 affects all users of the Download Monitor plugin for WordPress versions up to and including 4.7.60.
What kind of information is exposed by CVE-2022-45354?
CVE-2022-45354 may allow unauthorized actors to access sensitive information stored by the Download Monitor plugin.
Is there a workaround for CVE-2022-45354?
The recommended action for CVE-2022-45354 is to upgrade the plugin, as no effective workaround is provided for mitigating the vulnerability.