First published: Mon Jan 24 2022(Updated: )
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tipsandtricks-hq Simple Download Monitor | <3.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24696 is a vulnerability in the Simple Download Monitor WordPress plugin before version 3.9.9 that allows attackers to perform CSRF attacks.
CVE-2021-24696 allows attackers to perform CSRF attacks, which can lead to various malicious activities such as log disclosure and deletion, as well as unauthorized removal of thumbnail images.
CVE-2021-24696 has a severity level of 8.8 (high).
To fix CVE-2021-24696, you should update your Simple Download Monitor WordPress plugin to version 3.9.9 or later.
You can find more information about CVE-2021-24696 and its impact on the Simple Download Monitor plugin at the following reference: [CVE-2021-24696](https://wpscan.com/vulnerability/e94772af-39ac-4743-a556-52351ebda9fe)