CVE-2021-24786

HIGH NUCLEI

WordPress Download Monitor <4.4.5 - SQL Injection

Title source: llm

Description

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

Exploits (1)

exploitdb WORKING POC
by Ron Jost · pythonwebappsphp
https://www.exploit-db.com/exploits/50695

Nuclei Templates (1)

Download Monitor < 4.4.5 - SQL Injection
HIGHVERIFIEDby MrHarsh

Scores

CVSS v3 7.2
EPSS 0.0223
EPSS Percentile 84.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
wpchill/download_monitor < 4.4.5
Published Jan 03, 2022
Tracked Since Feb 18, 2026