← Back

CVE-2022-4972

nvd nist
Published: Oct 16, 2024Modified: Oct 30, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: security@wordfence.com (Secondary)

Description

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.

Affected (1)

1 product
Download Monitor
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.7.51

Timeline

No history available yet.