cleantalk
Vulnerabilities and Security Researches

Simple Download Monitor, CVE-2021-24696

CVE, Research URL

CVE-2021-24696

Published on
Jan 24, 2022
Research Description
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
Affected versions
Min -, max 3.9.11.
Status
vulnerable