WP Clinic
Entrar Registrarse

CVE · Medium

CVE-2021-24692 — Simple Download Monitor [simple-download-monitor] < 3.9.5

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2021-24692 Simple Download Monitor [simple-download-monitor] < 3.9.5 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,5 < 3.9.5 3.9.5 2021-09-02

CVE-2021-24692

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.