Vulnerability record · CVE-2021-23174 · published 28 January 2022
CVE-2021-23174: Download Monitor WordPress plugin persistent XSS via post_title and file version fields
Wpchill · Download Monitor
The Download Monitor WordPress plugin through version 4.4.6 stores attacker-controlled input from the post_title and downloadable_file_version[0] parameters without adequate sanitization, resulting in persistent cross-site scripting. Because the payload is stored, it executes for any user who later views the affected page, making it more dangerous than a reflected XSS.
Description
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires admin-level privileges and victim interaction, but the stored nature and very high EPSS score raise the practical risk.
What it is
The Download Monitor WordPress plugin through version 4.4.6 stores attacker-controlled input from the post_title and downloadable_file_version[0] parameters without adequate sanitization, resulting in persistent cross-site scripting. Because the payload is stored, it executes for any user who later views the affected page, making it more dangerous than a reflected XSS.
Impact
An attacker with admin-level access can inject script that runs in the browsers of other users, including higher-privileged accounts, enabling session theft, credential capture or arbitrary actions in the victim's context.
Attack surface
Reached over the network through the WordPress admin interface; the CVSS vector requires high privileges (PR:H) and user interaction (UI:R) from the victim who views the injected content.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high at 0.83853 (99.7th percentile), indicating elevated predicted exploitation activity.
What to do
- Update Download Monitor to a version later than 4.4.6, which is the last affected release named in the record.
- Restrict admin-level accounts to trusted personnel and review who holds admin+ roles.
- Apply input sanitization and output escaping on post_title and downloadable_file_version fields if custom code is involved.
- Deploy a web application firewall rule targeting stored XSS payloads in Download Monitor admin parameters.
Detection
- Search WordPress post and plugin metadata for script tags or event handlers in post_title and downloadable_file_version values.
- Monitor admin-side requests containing encoded script payloads in those parameters.
- Review web server and application logs for anomalous admin activity preceding stored content changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-23174 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-23174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.