First published: Fri Mar 29 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPChill Download Monitor | <4.9.5 | |
Download Monitor | <=4.9.4 | |
Download Monitor | <=4.9.4 |
Update to 4.9.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30501 is classified as a critical SQL Injection vulnerability affecting WPChill Download Monitor.
To fix CVE-2024-30501, update the Download Monitor plugin to the latest version beyond 4.9.4.
CVE-2024-30501 affects WPChill Download Monitor versions up to and including 4.9.4.
CVE-2024-30501 is an SQL Injection vulnerability that occurs due to improper neutralization of special elements in SQL commands.
Users of WPChill Download Monitor versions 4.9.4 and earlier are affected by CVE-2024-30501.