CVE-2024-8552: Download Monitor <= 5.0.9 - Missing Authorization to Authenticated (Subscriber+) Shop Enable
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableshop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop functionality.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8552?
CVE-2024-8552 has a high severity rating due to the potential for unauthorized data modification.
How do I fix CVE-2024-8552?
To fix CVE-2024-8552, update the Download Monitor plugin to version 5.0.10 or later.
Who is affected by CVE-2024-8552?
Authenticated users with Subscriber-level access are particularly affected by CVE-2024-8552.
What does CVE-2024-8552 allow attackers to do?
CVE-2024-8552 allows attackers to modify data without proper authorization.
Which versions of the Download Monitor plugin are vulnerable to CVE-2024-8552?
All versions of the Download Monitor plugin up to and including 5.0.9 are vulnerable to CVE-2024-8552.