Vulnerability Description
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tipsandtricks-Hq | Simple Download Monitor | < 3.9.5 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/d7bdaf2b-cdd9-4aee-b1bb-01728160ff25ExploitThird Party Advisory
- https://wpscan.com/vulnerability/d7bdaf2b-cdd9-4aee-b1bb-01728160ff25ExploitThird Party Advisory
FAQ
What is CVE-2021-24695?
CVE-2021-24695 is a vulnerability with a CVSS score of 7.5 (HIGH). The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to downl...
How severe is CVE-2021-24695?
CVE-2021-24695 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24695?
Check the references section above for vendor advisories and patch information. Affected products include: Tipsandtricks-Hq Simple Download Monitor.