First published: Mon Mar 14 2022(Updated: )
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Download Monitor by Ruhul Amin and Josh Lobe | <3.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24692 is a vulnerability in the Simple Download Monitor WordPress plugin before version 3.9.5.
The severity of CVE-2021-24692 is medium (6.5).
Users of Simple Download Monitor plugin before version 3.9.5 are affected by CVE-2021-24692.
CVE-2021-24692 allows users with a role as low as Contributor to download any file on the web server.
To fix CVE-2021-24692, upgrade Simple Download Monitor plugin to version 3.9.5 or higher.