CVE-2023-34007


WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload

Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.



We have discovered 1,555 live websites that are affected by CVE-2023-34007.

Contact us to get more info




Affected Software

Product  Download Monitor
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 4.8.3
Total Vulnerable Versions76
Vulnerable Domains1,555 live websites (8.98% of Download Monitor install base)


Common Weakness Enumeration


CWE-434 Unrestricted Upload of File with Dangerous Type


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-34007 and the relative popularity of websites


Details

  • Published - Dec 20, 2023
  • Updated - Dec 20, 2023

Credits

  • Tien Nguyen Anh (Patchstack Alliance) (finder)





Countries

United States366 websites



Germany263 websites
Japan99 websites
GB81 websites
France73 websites
Italy68 websites
Spain59 websites
Netherlands51 websites
Brazil33 websites
Canada31 websites

TLDs

.com577 websites
.de178 websites
.org108 websites
.net44 websites
.co.uk42 websites
.it40 websites
.es35 websites
.nl34 websites
.jp28 websites
.com.br27 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-34007 through included software libraries and plugins.



References


Websites affected by CVE-2023-34007

Top websites that are affected by CVE-2023-34007. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
********.com United States**,***
***.*******.com United States**,***
***************.org Netherlands**,***
***.****.org United States**,***
***.**************.fi Finland**,***
***********.com United States***,***
***.**********.**.uk GB***,***
**********.com South Africa***,***
***.****.org United States***,***
***********.org United States***,***
See full domain list