CVE-2021-24695: Simple Download Monitor < 3.9.6 - Unauthenticated Log Access
Published Nov 8, 2021
·Updated
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
Affected Software
1 affected component
Tipsandtricks-hq Simple Download Monitor Wordpress<3.9.5
Event History
Nov 8, 2021
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the Simple Download Monitor WordPress plugin vulnerability?
The vulnerability ID is CVE-2021-24695.
2
What is the severity of CVE-2021-24695?
The severity of CVE-2021-24695 is high with a CVSS score of 7.5.
3
How does CVE-2021-24695 impact the Simple Download Monitor WordPress plugin?
CVE-2021-24695 allows unauthenticated users to download and read logs containing sensitive information such as IP addresses and usernames.
4
Which version of the Simple Download Monitor WordPress plugin is affected by CVE-2021-24695?
The Simple Download Monitor WordPress plugin versions up to but excluding 3.9.6 are affected by CVE-2021-24695.
5
How can I fix the vulnerability CVE-2021-24695 in the Simple Download Monitor WordPress plugin?
To fix CVE-2021-24695, update the Simple Download Monitor plugin to version 3.9.6 or higher.