CVE-2024-3269Improper Authorization in Download Monitor

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 66.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 30

Description

The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages1 packages

CVEListV5wpchill/download_monitor4.9.13

🔴Vulnerability Details

1
CVEList
Download Monitor <= 4.9.13 - Missing Authorization2024-05-30
CVE-2024-3269 — Improper Authorization | cvebase