What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
Explanation of Vulnerability in Simple Terms
Download Monitor versions up to 4.9.4 contain a SQL injection vulnerability accessible to high-privilege users. An attacker with admin or equivalent access can inject malicious SQL through the plugin's database queries, potentially reading sensitive data from the WordPress database. The vulnerability requires administrative credentials to exploit.
What an attacker can do
Read sensitive data from the WordPress database using SQL injection.
Potential impact on your site
If a compromised admin account exists, attackers can extract sensitive database information including user credentials and private content.
Conditions required to exploit
Attacker must have high-privilege access (admin or equivalent role) to the WordPress site.
Key dates
External resources
Related vulnerabilities