CVE-2021-25059: Download Plugin < 2.0.0 - Subscriber+ Website Download
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25059?
CVE-2021-25059 is a vulnerability in the Download Plugin WordPress plugin before version 2.0.0 that allows unauthorized users to download a full copy of the website.
How severe is CVE-2021-25059?
CVE-2021-25059 has a severity rating of 4.3, which is considered medium.
Which software versions are affected by CVE-2021-25059?
The Download Plugin WordPress plugin versions up to and excluding 2.0.0 are affected by CVE-2021-25059.
How can the CVE-2021-25059 vulnerability be fixed?
To fix the CVE-2021-25059 vulnerability, it is recommended to update the Download Plugin WordPress plugin to version 2.0.0 or later.
Is there any additional information about CVE-2021-25059?
You can find additional information about CVE-2021-25059 at the following reference: [CVE-2021-25059 Reference](https://wpscan.com/vulnerability/b125a765-a6b6-421b-bd8a-effec12bc629)