← Vulnerability feed

Vulnerability record · CVE-2021-23174 · published 28 January 2022

CVE-2021-23174: Download Monitor WordPress plugin persistent XSS via post_title and file version fields

Wpchill · Download Monitor

The Download Monitor WordPress plugin through version 4.4.6 stores attacker-controlled input from the post_title and downloadable_file_version[0] parameters without adequate sanitization, resulting in persistent cross-site scripting. Because the payload is stored, it executes for any user who later views the affected page, making it more dangerous than a reflected XSS.

4.8 CVSS 3.1 Medium EPSS 84% · top 0.3% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score, v2 3.5
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityRequires admin-level privileges and victim interaction, but the stored nature and very high EPSS score raise the practical risk.

What it is

The Download Monitor WordPress plugin through version 4.4.6 stores attacker-controlled input from the post_title and downloadable_file_version[0] parameters without adequate sanitization, resulting in persistent cross-site scripting. Because the payload is stored, it executes for any user who later views the affected page, making it more dangerous than a reflected XSS.

Impact

An attacker with admin-level access can inject script that runs in the browsers of other users, including higher-privileged accounts, enabling session theft, credential capture or arbitrary actions in the victim's context.

Attack surface

Reached over the network through the WordPress admin interface; the CVSS vector requires high privileges (PR:H) and user interaction (UI:R) from the victim who views the injected content.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high at 0.83853 (99.7th percentile), indicating elevated predicted exploitation activity.

What to do

  • Update Download Monitor to a version later than 4.4.6, which is the last affected release named in the record.
  • Restrict admin-level accounts to trusted personnel and review who holds admin+ roles.
  • Apply input sanitization and output escaping on post_title and downloadable_file_version fields if custom code is involved.
  • Deploy a web application firewall rule targeting stored XSS payloads in Download Monitor admin parameters.

Detection

  • Search WordPress post and plugin metadata for script tags or event handlers in post_title and downloadable_file_version values.
  • Monitor admin-side requests containing encoded script payloads in those parameters.
  • Review web server and application logs for anomalous admin activity preceding stored content changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23174 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-34007Wpchill download monitor unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.EPSS 0.91%7.5CVE-2022-4972Wpchill download monitor missing authorization vulnerabilityThe Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related …EPSS 0.47%7.5CVE-2022-45354Wpchill download monitor information exposure vulnerabilityExposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a th…EPSS 38%7.2CVE-2024-30501Wpchill download monitor sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Dow…EPSS 0.61%7.2CVE-2021-24786Wpchill download monitor sql injection vulnerabilityThe Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL stateme…EPSS 17%6.8CVE-2021-31567Wpchill download monitor information exposure vulnerabilityAuthenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows a…EPSS 1.4%5.4CVE-2021-36920Wpchill download monitor cross-site scripting vulnerabilityAuthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).EPSS 0.57%4.9CVE-2023-31219Wpchill download monitor server-side request forgery (ssrf) vulnerabilityServer-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2021-23174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.