CVE-2021-24786
HIGH NUCLEIWordPress Download Monitor <4.4.5 - SQL Injection
Title source: llmDescription
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Exploits (1)
Nuclei Templates (1)
Download Monitor < 4.4.5 - SQL Injection
HIGHVERIFIEDby MrHarsh
Scores
CVSS v3
7.2
EPSS
0.0223
EPSS Percentile
84.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
wpchill/download_monitor
< 4.4.5
Published
Jan 03, 2022
Tracked Since
Feb 18, 2026