CVE-2021-24696: Simple Download Monitor < 3.9.9 - Multiple CSRF
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24696?
CVE-2021-24696 is a vulnerability in the Simple Download Monitor WordPress plugin before version 3.9.9 that allows attackers to perform CSRF attacks.
How does CVE-2021-24696 impact the Simple Download Monitor plugin?
CVE-2021-24696 allows attackers to perform CSRF attacks, which can lead to various malicious activities such as log disclosure and deletion, as well as unauthorized removal of thumbnail images.
What is the severity level of CVE-2021-24696?
CVE-2021-24696 has a severity level of 8.8 (high).
How can I fix CVE-2021-24696?
To fix CVE-2021-24696, you should update your Simple Download Monitor WordPress plugin to version 3.9.9 or later.
Is there any additional information about CVE-2021-24696?
You can find more information about CVE-2021-24696 and its impact on the Simple Download Monitor plugin at the following reference: [CVE-2021-24696](https://wpscan.com/vulnerability/e94772af-39ac-4743-a556-52351ebda9fe)