CVE-2024-10399: Download Monitor <= 5.0.13 - Missing Authorization to Sensitive Information Exposure
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxsearchusers function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames and emails of site users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10399?
CVE-2024-10399 is considered a moderate severity vulnerability due to unauthorized modification of data.
How do I fix CVE-2024-10399?
To fix CVE-2024-10399, update the Download Monitor plugin to version 5.0.14 or later.
Who is affected by CVE-2024-10399?
All versions of the Download Monitor plugin up to and including 5.0.13 are affected by CVE-2024-10399.
What is affected by CVE-2024-10399?
CVE-2024-10399 affects the Download Monitor plugin for WordPress, specifically the ajax_search_users function.
What types of attacks are possible with CVE-2024-10399?
CVE-2024-10399 allows authenticated attackers with Subscriber-level access to modify data due to a missing capability check.