WP Clinic
Entrar Registrarse

CVE · High

CVE-2021-24695 — Simple Download Monitor [simple-download-monitor] < 3.9.11

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2021-24695 Simple Download Monitor [simple-download-monitor] < 3.9.11 Solicitud directa (Forced Browsing / navegación forzada) Alta 7,5 < 3.9.11 3.9.11 2021-10-05

CVE-2021-24695

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.