CVE-2022-45354
MEDIUM EXPLOITED NUCLEIWPChill Download Monitor < 4.7.60 - Exposure of Sensitive Information to an Unauthorized Actor
Title source: llmExploitation Summary
CVE-2022-45354 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including RandomRobbieBF. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a working PoC for CVE-2022-45354, which exploits an information exposure vulnerability in the Download Monitor WordPress plugin via its REST API. The PoC includes a Python script to extract sensitive user data and download files.
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
Exploits (1)
This repository contains a working PoC for CVE-2022-45354, which exploits an information exposure vulnerability in the Download Monitor WordPress plugin via its REST API. The PoC includes a Python script to extract sensitive user data and download files.
Nuclei Templates (1)
html:"/wp-content/plugins/download-monitor/" || http.html:"/wp-content/plugins/download-monitor/"
body="/wp-content/plugins/download-monitor/"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N