CVE-2022-45354 Scanner

Detects 'Sensitive Information Exposure' vulnerability in Download Monitor affects v. <= 4.7.60


Download Monitor is a widely-used WordPress plugin designed for managing and tracking file downloads on WordPress sites. It is utilized by website owners to offer downloadable content while keeping track of download counts and user access. This plugin is essential for businesses, educational platforms, and content creators who need to securely distribute files to their audience. It offers features like download logging, user access control, and file protection to prevent unauthorized access. The plugin enhances WordPress sites by providing an organized and efficient way to handle downloadable content.

CVE-2022-45354 identifies a high-severity Sensitive Information Exposure vulnerability in versions up to and including 4.7.60 of the Download Monitor WordPress plugin. This vulnerability allows unauthenticated attackers to access sensitive data through the REST API, including user reports, download reports, and detailed user data such as email, role, and ID. This exposure does not include passwords but can lead to significant privacy breaches and unauthorized access to restricted information.

The vulnerability arises because the plugin does not properly restrict access to the REST API endpoint /wp-json/download-monitor/v1/user_data. As a result, sensitive information about users and downloads can be accessed without authentication. The exposed data includes, but is not limited to, user email addresses, roles, IDs, and download activities. This oversight in API security can be exploited by sending a simple HTTP GET request to the vulnerable endpoint.

Exploiting this vulnerability can lead to various adverse impacts, including data breaches, privacy violations, and potentially unauthorized actions on the website. Attackers could use the exposed information for phishing attacks, identity theft, or to gain further access to the website's administrative functions. The exposure of user and download data undermines the confidentiality and integrity of the website, posing a significant risk to both site owners and users.

