CVE-2021-24692: Simple Download Monitor < 3.9.5 - Contributor+ Arbitrary File Download via Path Traversal
Published Mar 14, 2022
·Updated
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
Affected Software
1 affected component
Tipsandtricks-hq Simple Download Monitor Wordpress<3.9.5
Event History
Mar 14, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24692?
CVE-2021-24692 is a vulnerability in the Simple Download Monitor WordPress plugin before version 3.9.5.
2
What is the severity of CVE-2021-24692?
The severity of CVE-2021-24692 is medium (6.5).
3
Who is affected by CVE-2021-24692?
Users of Simple Download Monitor plugin before version 3.9.5 are affected by CVE-2021-24692.
4
What is the impact of CVE-2021-24692?
CVE-2021-24692 allows users with a role as low as Contributor to download any file on the web server.
5
How can I fix CVE-2021-24692?
To fix CVE-2021-24692, upgrade Simple Download Monitor plugin to version 3.9.5 or higher.