CVE-2023-31219


WordPress Download Monitor Plugin <= 4.8.1 is vulnerable to Server Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.



We have discovered 1,486 live websites that are affected by CVE-2023-31219.

Contact us to get more info




Affected Software

Product  Download Monitor
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 4.8.1
Total Vulnerable Versions76
Vulnerable Domains1,486 live websites (8.58% of Download Monitor install base)


Common Weakness Enumeration


CWE-918 Server-Side Request Forgery (SSRF)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-31219 and the relative popularity of websites


Details

  • Published - Nov 13, 2023
  • Updated - Nov 13, 2023

Credits

  • Mika (Patchstack Alliance) (finder)





Countries

United States350 websites



Germany253 websites
Japan93 websites
GB77 websites
France69 websites
Italy62 websites
Spain53 websites
Netherlands49 websites
Brazil32 websites
Canada31 websites

TLDs

.com553 websites
.de170 websites
.org103 websites
.co.uk42 websites
.net41 websites
.it37 websites
.nl34 websites
.es30 websites
.jp27 websites
.com.br26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-31219 through included software libraries and plugins.



References


Websites affected by CVE-2023-31219

Top websites that are affected by CVE-2023-31219. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
********.com United States**,***
***.*******.com United States**,***
***************.org Netherlands**,***
***.****.org United States**,***
***.**************.fi Finland**,***
***********.com United States***,***
***.**********.**.uk GB***,***
**********.com South Africa***,***
***.****.org United States***,***
***********.org United States***,***
See full domain list