Unauthorized Modification of Data in Download Monitor Plugin for WordPress Allows Attackers to Access Site Users' Data
CVE-2024-10399
What is CVE-2024-10399?
The Download Monitor plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check in the ajax_search_users function. This vulnerability affects all versions up to and including 5.0.13. Authenticated attackers with Subscriber-level access and above can exploit this flaw, allowing them to retrieve sensitive information such as usernames and email addresses of site users. Site administrators should prioritize updating the plugin to mitigate potential risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Download Monitor * <= 5.0.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved