First published: Mon Nov 28 2022(Updated: )
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss Download Plugin | <2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25059 is a vulnerability in the Download Plugin WordPress plugin before version 2.0.0 that allows unauthorized users to download a full copy of the website.
CVE-2021-25059 has a severity rating of 4.3, which is considered medium.
The Download Plugin WordPress plugin versions up to and excluding 2.0.0 are affected by CVE-2021-25059.
To fix the CVE-2021-25059 vulnerability, it is recommended to update the Download Plugin WordPress plugin to version 2.0.0 or later.
You can find additional information about CVE-2021-25059 at the following reference: [CVE-2021-25059 Reference](https://wpscan.com/vulnerability/b125a765-a6b6-421b-bd8a-effec12bc629)