WPHizmet

Eklenti güvenlik geçmişi

Download Monitor güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Download Monitor eklentisi için 23 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 9 tanesi kritik veya yüksek önemde, 6 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 5.3.2.

Toplam kayıt
23
Kritik veya yüksek
9
Oturumsuz istismar
6
Son kayıt
2 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-100182Yüksek · 7,22 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.2.10 ve öncesi · Oturum açmadan istismar edilebilir

    The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to trick an authenticated Administrator into visiting an attacker-controlled page that targets an open Download edit screen, after which the payload is persisted unfiltered via the Administrator's unfiltered_html capability and later emitted verbatim to the frontend by the [download_data] shortcode's unescaped post_content render path.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-16608Orta · 5,38 Ağustos 2026

    eksik yetki denetimi

    Etkilenen sürümler: 5.2.6 öncesi · Oturum açmadan istismar edilebilir

    The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.

  • CVE-2026-39489Orta · 4,416 Haziran 2026

    rastgele dosya okuma

    Etkilenen sürümler: 5.1.9 ve öncesi

    Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.

  • CVE-2026-39486Yüksek · 8,58 Nisan 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 5.1.8 ve öncesi

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download Monitor: from n/a through <= 5.1.8.

  • CVE-2026-4401Orta · 5,48 Nisan 2026

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 5.1.10 ve öncesi · Oturum açmadan istismar edilebilir

    The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for unauthenticated attackers to delete, disable, or enable approved download paths via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

  • CVE-2026-3124Yüksek · 7,530 Mart 2026

    yetkisiz nesne erişimi (IDOR)

    Etkilenen sürümler: 5.1.7 ve öncesi · Oturum açmadan istismar edilebilir

    The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between the PayPal transaction token and the local order, allowing theft of paid digital goods by paying a minimal amount for a low-cost item and using that payment token to finalize a high-value order.

  • CVE-2025-47439Yüksek · 7,57 Mayıs 2025

    yerel dosya dahil etme (LFI)

    Etkilenen sürümler: 5.0.22 ve öncesi

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.

  • CVE-2024-10399Orta · 4,330 Ekim 2024

    eksik yetki denetimi

    Etkilenen sürümler: 5.0.13 ve öncesi

    The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames and emails of site users.

  • CVE-2024-10092Orta · 4,326 Ekim 2024

    eksik yetki denetimi

    Etkilenen sürümler: 5.0.12 ve öncesi

    The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke existing API keys and generate new ones.

  • CVE-2022-4972Yüksek · 7,516 Ekim 2024

    eksik yetki denetimi

    Etkilenen sürümler: 4.7.51 ve öncesi · Oturum açmadan istismar edilebilir

    The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.

  • CVE-2024-8552Orta · 4,326 Eylül 2024

    eksik yetki denetimi

    Etkilenen sürümler: 5.0.9 ve öncesi

    The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop functionality.

  • CVE-2024-3269Orta · 5,430 Mayıs 2024

    eksik yetki denetimi

    Etkilenen sürümler: 4.9.13 ve öncesi

    The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.

  • CVE-2024-30501Yüksek · 7,229 Mart 2024

    SQL enjeksiyonu

    Etkilenen sürümler: 4.9.4 ve öncesi

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.

  • CVE-2022-45354Yüksek · 7,59 Ocak 2024

    hassas bilgi ifşası

    Etkilenen sürümler: 4.7.60 ve öncesi · Oturum açmadan istismar edilebilir

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

  • CVE-2023-34007Yüksek · 8,820 Aralık 2023

    kısıtlamasız dosya yükleme

    Etkilenen sürümler: 4.8.3 ve öncesi

    Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.

  • CVE-2023-31219Orta · 4,913 Kasım 2023

    sunucu taraflı istek sahteciliği (SSRF)

    Etkilenen sürümler: 4.8.1 ve öncesi

    Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.

  • CVE-2022-2981Orta · 4,911 Ekim 2022

    hassas bilgi ifşası

    Etkilenen sürümler: 4.5.98 öncesi

    The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

  • CVE-2022-2222Orta · 4,917 Temmuz 2022

    hassas bilgi ifşası

    Etkilenen sürümler: 4.5.91 öncesi

    The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

  • CVE-2021-31567Orta · 6,828 Ocak 2022

    rastgele dosya okuma

    Etkilenen sürümler: 4.4.6 ve öncesi

    Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.

  • CVE-2021-36920Orta · 5,414 Ocak 2022

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 4.4.6 ve öncesi

    Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).

  • CVE-2021-24786Yüksek · 7,23 Ocak 2022

    SQL enjeksiyonu

    Etkilenen sürümler: 4.4.5 öncesi

    The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

  • CVE-2013-509810 Ağustos 2013

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.3.6.2 öncesi

    Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.

  • CVE-2013-326210 Ağustos 2013

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.3.6.2 öncesi

    Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.