CVE-2012-4768
NUCLEIWordPress Download Monitor <3.3.5.9 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Chris Cooper · textwebappsphp
https://www.exploit-db.com/exploits/37787
Nuclei Templates (1)
WordPress Plugin Download Monitor < 3.3.5.9 - Cross-Site Scripting
MEDIUMby daffainfo
Shodan:
http.html:"/wp-content/plugins/download-monitor/"
FOFA:
body="/wp-content/plugins/download-monitor/"
References (6)
Scores
EPSS
0.0194
EPSS Percentile
83.5%
Details
CWE
CWE-79
Status
published
Products (1)
mikejolley/download_monitor
3.3.5.7
Published
Sep 04, 2014
Tracked Since
Feb 18, 2026