Update the WordPress Download Monitor plugin to the latest available version (at least 4.4.7).
minhtuanact discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.4.7.
Authenticated Arbitrary File Download vulnerability
19.09.2022
Authenticated Arbitrary File Download vulnerability
27.06.2022
Authenticated Persistent CrossSite Scripting (XSS) vulnerability
29.10.2021
Authenticated Arbitrary File Download vulnerability
29.10.2021
SQL Injection (SQLi) vulnerability
20.10.2021