CVE-2021-23174


WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability

Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].



We have discovered 39 live websites that are affected by CVE-2021-23174.

Contact us to get more info




Affected Software

Product  Download Monitor
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 4.4.6
Total Vulnerable Versions76
Vulnerable Domains39 live websites (0.23% of Download Monitor install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2021-23174 and the relative popularity of websites


Details

  • Published - Oct 29, 2021
  • Updated - Feb 13, 2023

Credits

  • FearZzZz (Patchstack Alliance) (finder)





Countries

United States8 websites



Japan8 websites
France3 websites
Austria2 websites
Canada2 websites
Germany2 websites
Spain2 websites
Italy2 websites
Poland2 websites
Australia1 websites

TLDs

.com14 websites
.jp5 websites
.pl2 websites
.de2 websites
.net2 websites
.ca1 websites
.co.jp1 websites
.co.uk1 websites
.com.au1 websites
.dk1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2021-23174 through included software libraries and plugins.



References


Websites affected by CVE-2021-23174

Top websites that are affected by CVE-2021-23174. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*******.com United States**,***
***.*************.net United States***,***
*************.com United States*,***,***
****.de Germany*,***,***
******.fr France*,***,***
***********.net Japan*,***,***
***.***.cz Czech Republic*,***,***
***.**********.gr Greece*,***,***
***********.com Austria*,***,***
***.*****.jp Japan*,***,***
See full domain list