CVE-2022-45354

MEDIUM EXPLOITED NUCLEI

Wpchill Download Monitor < 4.7.60 - Information Disclosure

Title source: rule

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

Exploits (1)

nomisec WORKING POC
by RandomRobbieBF · infoleak
https://github.com/RandomRobbieBF/CVE-2022-45354

Nuclei Templates (1)

Download Monitor <= 4.7.60 - Sensitive Information Exposure
HIGHVERIFIEDby DhiyaneshDK
Shodan: html:"/wp-content/plugins/download-monitor/" || http.html:"/wp-content/plugins/download-monitor/"
FOFA: body="/wp-content/plugins/download-monitor/"

Scores

CVSS v3 5.3
EPSS 0.8762
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Exploitation Intel

VulnCheck KEV 2023-05-10

Classification

CWE
CWE-200
Status published

Affected Products (1)

wpchill/download_monitor < 4.7.60

Timeline

Published Jan 08, 2024
Tracked Since Feb 18, 2026