Eklenti güvenlik geçmişi
Download Monitor güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Download Monitor eklentisi için 23 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 9 tanesi kritik veya yüksek önemde, 6 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 5.3.2.
- Toplam kayıt
- 23
- Kritik veya yüksek
- 9
- Oturumsuz istismar
- 6
- Son kayıt
- 2 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 5.2.10 ve öncesi · Oturum açmadan istismar edilebilir
The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to trick an authenticated Administrator into visiting an attacker-controlled page that targets an open Download edit screen, after which the payload is persisted unfiltered via the Administrator's unfiltered_html capability and later emitted verbatim to the frontend by the [download_data] shortcode's unescaped post_content render path.
Türkçe kayıt ve ne yapmalıeksik yetki denetimi
Etkilenen sürümler: 5.2.6 öncesi · Oturum açmadan istismar edilebilir
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
rastgele dosya okuma
Etkilenen sürümler: 5.1.9 ve öncesi
Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.
SQL enjeksiyonu
Etkilenen sürümler: 5.1.8 ve öncesi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download Monitor: from n/a through <= 5.1.8.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 5.1.10 ve öncesi · Oturum açmadan istismar edilebilir
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for unauthenticated attackers to delete, disable, or enable approved download paths via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 5.1.7 ve öncesi · Oturum açmadan istismar edilebilir
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between the PayPal transaction token and the local order, allowing theft of paid digital goods by paying a minimal amount for a low-cost item and using that payment token to finalize a high-value order.
yerel dosya dahil etme (LFI)
Etkilenen sürümler: 5.0.22 ve öncesi
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.
eksik yetki denetimi
Etkilenen sürümler: 5.0.13 ve öncesi
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames and emails of site users.
eksik yetki denetimi
Etkilenen sürümler: 5.0.12 ve öncesi
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke existing API keys and generate new ones.
eksik yetki denetimi
Etkilenen sürümler: 4.7.51 ve öncesi · Oturum açmadan istismar edilebilir
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.
eksik yetki denetimi
Etkilenen sürümler: 5.0.9 ve öncesi
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop functionality.
eksik yetki denetimi
Etkilenen sürümler: 4.9.13 ve öncesi
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.
SQL enjeksiyonu
Etkilenen sürümler: 4.9.4 ve öncesi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
hassas bilgi ifşası
Etkilenen sürümler: 4.7.60 ve öncesi · Oturum açmadan istismar edilebilir
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
kısıtlamasız dosya yükleme
Etkilenen sürümler: 4.8.3 ve öncesi
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
sunucu taraflı istek sahteciliği (SSRF)
Etkilenen sürümler: 4.8.1 ve öncesi
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.
hassas bilgi ifşası
Etkilenen sürümler: 4.5.98 öncesi
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
hassas bilgi ifşası
Etkilenen sürümler: 4.5.91 öncesi
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
rastgele dosya okuma
Etkilenen sürümler: 4.4.6 ve öncesi
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 4.4.6 ve öncesi
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
SQL enjeksiyonu
Etkilenen sürümler: 4.4.5 öncesi
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
- CVE-2013-509810 Ağustos 2013
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.6.2 öncesi
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
- CVE-2013-326210 Ağustos 2013
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.6.2 öncesi
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.