WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload
CVE-2023-34007
9.9CRITICAL
What is CVE-2023-34007?
The WPChill Download Monitor plugin allows for unauthorized upload of potentially harmful files. This vulnerability can be exploited by attackers to upload arbitrary files, which may lead to unauthorized execution of code and compromise the site’s security. Affected versions include all prior to 4.8.3, posing risks to any installations using the plugin.
Affected Version(s)
Download Monitor <= 4.8.3