The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-05-30T03:34:29.217Z

Updated: 2024-08-01T20:05:08.405Z

Reserved: 2024-04-03T17:49:17.510Z

Link: CVE-2024-3269

cve-icon Vulnrichment

Updated: 2024-08-01T20:05:08.405Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-30T04:15:10.697

Modified: 2024-11-21T09:29:17.153

Link: CVE-2024-3269

cve-icon Redhat

No data.