CVE-2021-24698: Simple Download Monitor < 3.9.6 - Arbitrary Thumbnails Removal
Published Nov 8, 2021
·Updated
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
Affected Software
1 affected component
Tipsandtricks-hq Simple Download Monitor Wordpress<3.9.6
Event History
Nov 8, 2021
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-24698.
2
What is the severity of CVE-2021-24698?
The severity of CVE-2021-24698 is medium with a score of 4.3.
3
What is the affected software by CVE-2021-24698?
The affected software is the Simple Download Monitor WordPress plugin version up to 3.9.6.
4
What is the impact of CVE-2021-24698?
The impact of CVE-2021-24698 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own.
5
How can I fix CVE-2021-24698?
To fix CVE-2021-24698, update the Simple Download Monitor plugin to version 3.9.6 or higher.