CVE-2024-10092: Download Monitor <= 5.0.12 - Missing Authorization to API Key Manipulation
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxhandleapikeyactions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke existing API keys and generate new ones.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10092?
CVE-2024-10092 is rated as a medium severity vulnerability affecting the Download Monitor plugin for WordPress.
How do I fix CVE-2024-10092?
To fix CVE-2024-10092, update the Download Monitor plugin to version 5.0.13 or higher, which includes the necessary capability checks.
Who is affected by CVE-2024-10092?
CVE-2024-10092 affects all versions of the Download Monitor plugin for WordPress up to and including version 5.0.12.
What type of attack is possible with CVE-2024-10092?
CVE-2024-10092 allows authenticated attackers, even with Subscriber roles, to modify data without proper permissions.
Is CVE-2024-10092 a remote exploit?
CVE-2024-10092 is not a remote exploit; it requires an authenticated user with minimal permissions to exploit the vulnerability.