S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 28, 2026

CVE-2021-24786 Scanner

CVE-2021-24786 Scanner - SQL Injection vulnerability in Download Monitor

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24786
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Download Monitor
AFFECTED< 4.4.5SAFE ✓≥ 4.4.5
Updated Aug 21, 2026View on NVD →
Detail

The Download Monitor plugin is a widely-used WordPress plugin designed to manage downloads and monitor access. It is typically utilized by website administrators who need an efficient way to track file downloads. This plugin provides comprehensive download management features such as upload, download logs, and custom links. Its user-friendly interface allows even non-technical users to manage downloads easily. Website owners worldwide use it to enhance the download capabilities of their WordPress sites. It is a popular choice for sites that require sophisticated download tracking.

The SQL Injection vulnerability detected in the Download Monitor plugin arises due to insufficient escaping on user-supplied parameters. This allows malicious actors to add unauthorized SQL commands to existing queries. Attackers leveraging this vulnerability can gain access to sensitive information stored within a website's database. This vulnerability is particularly dangerous because it does not require any direct interaction from the end-user once it has been set in motion. The vulnerability's impact is mitigated by its requirement for authenticated access with administrator-level permissions to exploit.

The Download Monitor plugin's SQL Injection vulnerability is specific to the orderby' parameter prior to version 4.4.5. Attackers can exploit this endpoint to append arbitrary SQL commands by failing to escape input properly. This leaves the SQL queries open to manipulation, allowing for unauthorized data extraction or modification. The vulnerable endpoint is part of the plugin's admin panel accessed via specific HTTP requests. The improper preparation of SQL statements, combined with hosted untrusted input, leads to the technical breach. The issue revolves around SQL queries executed without adequate input sanitization, resulting in potential database access for attackers.

If exploited, the SQL Injection vulnerability in Download Monitor could lead to unauthorized data access, data corruption, or data deletion. Attackers could extract sensitive user information, manipulate data records, or completely delete important database contents. Running malicious SQL commands could compromise entire databases, leading to severe data breaches. The website's functionality and reliability might be impaired due to data manipulation. Ultimately, the consequence of the vulnerability's exploitation could be reputational damage and loss of trust for website administrators.

REFERENCES

Solution Advice
  • Update the Download Monitor plugin to version 4.4.5 or later.
  • Implement proper input validation and sanitization for all user inputs.
  • Regularly audit plugins for known vulnerabilities and ensure timely updates.
  • Use a Web Application Firewall (WAF) to detect and block malicious requests.
  • Educate administrators about safe plugin usage and recognize potential security threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.