Description
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31860 | The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data. |
References
History
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T20:05:08.405Z
Reserved: 2024-04-03T17:49:17.510Z
Link: CVE-2024-3269
Updated: 2024-08-01T20:05:08.405Z
Status : Awaiting Analysis
Published: 2024-05-30T04:15:10.697
Modified: 2024-11-21T09:29:17.153
Link: CVE-2024-3269
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:01:05Z
Weaknesses
No weakness.
EUVD