Simple Download Monitor, CVE-2021-24696
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jan 24, 2022
- Research Description
- The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
- Affected versions
-
Min -, max 3.9.11.
- Status
-
vulnerable