CVE-2024-3269: Download Monitor <= 4.9.13 - Missing Authorization
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlmuninstallplugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3269?
CVE-2024-3269 has a medium severity level due to potential unauthorized access by authenticated attackers.
How do I fix CVE-2024-3269?
To fix CVE-2024-3269, update the Download Monitor plugin to version 4.9.14 or later where the vulnerability has been addressed.
Who is affected by CVE-2024-3269?
CVE-2024-3269 affects all versions of the Download Monitor plugin up to and including 4.9.13.
What does CVE-2024-3269 allow an attacker to do?
CVE-2024-3269 allows authenticated attackers to uninstall the Download Monitor plugin due to a missing capability check.
Is CVE-2024-3269 an easy vulnerability to exploit?
Yes, CVE-2024-3269 can be easily exploited by authenticated users with minimal technical skills.