CVE-2021-24694: Simple Download Monitor < 3.9.11 - Contributor+ Stored Cross-Site Scripting via Shortcodes
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "cssclass" argument of sdmdownload shortcode, 2) "class" or "placeholder" argument of sdmsearchform shortcode.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24694?
CVE-2021-24694 refers to a vulnerability in the Simple Download Monitor WordPress plugin that allows users with low privileges to perform Stored Cross-Site Scripting attacks.
What is the severity of CVE-2021-24694?
The severity of CVE-2021-24694 is rated as medium with a CVSS score of 5.4.
How does CVE-2021-24694 impact Simple Download Monitor plugin?
CVE-2021-24694 allows users with a role as low as Contributor to exploit certain arguments of shortcodes in the Simple Download Monitor plugin, leading to Stored Cross-Site Scripting attacks.
Which version of Simple Download Monitor is affected by CVE-2021-24694?
Versions up to and excluding 3.9.11 of the Simple Download Monitor plugin are affected by CVE-2021-24694.
Is there a fix available for CVE-2021-24694?
Yes, upgrading to version 3.9.11 or higher of the Simple Download Monitor plugin fixes the CVE-2021-24694 vulnerability.