Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown

CVE-2021-24693

Disclosure Date: November 08, 2021 (last updated November 28, 2024)
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin
Attacker Value
Unknown

CVE-2021-24695

Disclosure Date: November 08, 2021 (last updated November 28, 2024)
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
Attacker Value
Unknown

CVE-2021-31567

Disclosure Date: October 29, 2021 (last updated October 07, 2023)
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
Attacker Value
Unknown

CVE-2021-23174

Disclosure Date: October 29, 2021 (last updated September 17, 2024)
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
Attacker Value
Unknown

CVE-2020-5651

Disclosure Date: October 21, 2020 (last updated November 28, 2024)
SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
Attacker Value
Unknown

CVE-2020-5650

Disclosure Date: October 21, 2020 (last updated November 28, 2024)
Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
Attacker Value
Unknown

CVE-2015-9296

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
0
Attacker Value
Unknown

CVE-2018-5212

Disclosure Date: January 04, 2018 (last updated November 26, 2024)
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
0
Attacker Value
Unknown

CVE-2018-5213

Disclosure Date: January 04, 2018 (last updated November 26, 2024)
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
0
Attacker Value
Unknown

CVE-2012-4768

Disclosure Date: September 04, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
0