The Download Monitor WordPress plugin versions up to and including 5.1.10 contains a Cross-Site Request Forgery vulnerability in its download path management functions. The flaw stems from missing nonce verification in the actions_handler() and bulk_actions_handler() methods within class-dlm-downloads-path.php, enabling unauthenticated attackers to manipulate approved download paths if they can deceive site administrators into clicking a malicious link. The vulnerability carries a CVSS 3.1 score of 5.4 (Medium) and is network-accessible with low attack complexity, requiring only user interaction from an administrator. The attack does not require privileges to initiate but results in integrity and availability impacts, allowing deletion, disabling, or enabling of download paths without authorization. There is currently no evidence of active exploitation in the wild, as indicated by the absence from the Known Exploited Vulnerabilities catalog and its inactive status on industry hot lists. The extremely low EPSS score of 0.00022 suggests minimal real-world exploitation activity and community attention at this time, though organizations running vulnerable versions should prioritize patching to prevent potential abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 5.1.10CPE match | cpe:2.3:a:wpchill:download_monitor:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.