← back
CVE-2022-2222CWE-552

Download Monitor < 4.5.91 - Admin+ Arbitrary File Download

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.1%
exploitation probability
1.1%top 39% of all CVEs
observed exploitation
nono source reports it
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.