What the vulnerability does
01Description
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
Explanation of Vulnerability in Simple Terms
02Summary
A high-privilege user can read sensitive data from other parts of the system due to insufficient access controls. The vulnerability requires administrative or equivalent credentials to exploit. The impact is limited to confidentiality; the attacker cannot modify or delete data. Scope is changed, meaning the breach may extend beyond the vulnerable component itself.
What an attacker can do
03Attacker Capabilities
Read sensitive information from other system components with high-level privileges.
Potential impact on your site
04Site Impact
Administrators or high-privilege accounts could leak sensitive data; patch status and affected product unknown.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative or equivalent credentials; no user interaction required.
Key dates
06Disclosure timeline
January 28, 2022
CVE published
April 28, 2026
Record updated