← Back to CVE List

CVE-2022-4972

Published: 2024-10-16T07:15Z
Last Modified: 2024-10-30T16:34Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt