CVE-2022-45354

MEDIUM EXPLOITED NUCLEI

WPChill Download Monitor < 4.7.60 - Exposure of Sensitive Information to an Unauthorized Actor

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-45354 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including RandomRobbieBF. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a working PoC for CVE-2022-45354, which exploits an information exposure vulnerability in the Download Monitor WordPress plugin via its REST API. The PoC includes a Python script to extract sensitive user data and download files.

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

Exploits (1)

nomisec WORKING POC
by RandomRobbieBF · infoleak
https://github.com/RandomRobbieBF/CVE-2022-45354

This repository contains a working PoC for CVE-2022-45354, which exploits an information exposure vulnerability in the Download Monitor WordPress plugin via its REST API. The PoC includes a Python script to extract sensitive user data and download files.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Download Monitor WordPress plugin <= 4.7.60
No auth needed
Prerequisites: Access to the WordPress REST API endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Download Monitor <= 4.7.60 - Sensitive Information Exposure
HIGHVERIFIEDby DhiyaneshDK
Shodan: html:"/wp-content/plugins/download-monitor/" || http.html:"/wp-content/plugins/download-monitor/"
FOFA: body="/wp-content/plugins/download-monitor/"

Scores

CVSS v3 5.3
EPSS 0.3808
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2023-05-10
CWE
CWE-200
Status published
Products (2)
WPChill/Download Monitor < 4.7.60
wpchill/download_monitor < 4.7.60
Published Jan 08, 2024
Tracked Since Feb 18, 2026