Vulnerability Description
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tipsandtricks-Hq | Simple Download Monitor | < 3.9.9 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/e94772af-39ac-4743-a556-52351ebda9feExploitThird Party Advisory
- https://wpscan.com/vulnerability/e94772af-39ac-4743-a556-52351ebda9feExploitThird Party Advisory
FAQ
What is CVE-2021-24696?
CVE-2021-24696 is a vulnerability with a CVSS score of 8.8 (HIGH). The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log dis...
How severe is CVE-2021-24696?
CVE-2021-24696 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24696?
Check the references section above for vendor advisories and patch information. Affected products include: Tipsandtricks-Hq Simple Download Monitor.