CVE-2021-24703: Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwappluginactivate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24703?
CVE-2021-24703 is a vulnerability in the Download Plugin WordPress plugin before version 1.6.1.
What is the severity of CVE-2021-24703?
The severity of CVE-2021-24703 is medium, with a CVSS score of 5.7.
How does CVE-2021-24703 affect the Download Plugin WordPress plugin?
CVE-2021-24703 allows any authenticated users, such as subscribers, to activate plugins that are already installed.
How can I fix CVE-2021-24703?
To fix CVE-2021-24703, update the Download Plugin WordPress plugin to version 1.6.1 or higher.
Where can I find more information about CVE-2021-24703?
You can find more information about CVE-2021-24703 at this reference link: [https://wpscan.com/vulnerability/4ed8296e-1306-481f-9a22-723b051122c0](https://wpscan.com/vulnerability/4ed8296e-1306-481f-9a22-723b051122c0)