Update the WordPress Download Monitor plugin to the latest available version (at least 4.5.98).
Raad Haddad (Cloudyrion GmbH) discovered and reported this Arbitrary File Download vulnerability in WordPress Download Monitor Plugin. This could allow a malicious actor to download any file from your website. This includes but is not limited to files that contain login credentials or backup files. This vulnerability has been fixed in version 4.5.98.
Authenticated Arbitrary File Download vulnerability
27.06.2022
Authenticated Persistent CrossSite Scripting (XSS) vulnerability
29.10.2021
Authenticated Arbitrary File Download vulnerability
29.10.2021
Authenticated Reflected CrossSite Scripting (XSS) vulnerability
29.10.2021
SQL Injection (SQLi) vulnerability
20.10.2021