SoFunction
Updated on 2025-04-10

WordPress download monitoring plugin id parameter SQL injection vulnerability

describe:
BUGTRAQ ID: 28975

WordPress is a free forum blog system.

The download monitoring plugin wp-download_monitor/ in WordPress is used in SQL queries without properly filtering input to id parameters, which allows remote attackers to perform SQL injection attacks by manipulating SQL queries.