Base de Datos de CVE /
CVE-2021-24696
CVE · High
CVE-2021-24696 — Simple Download Monitor [simple-download-monitor] < 3.9.11
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2021-24696
|
Simple Download Monitor [simple-download-monitor] < 3.9.11 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
8,8
|
< 3.9.11
|
3.9.11 |
2021-12-21 |
—
|
CVE-2021-24696
Update the WordPress Simple Download Monitor to the latest available version (at least 3.9.9).
apple502j discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.9.9.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Escanea tu sitio WordPress gratis
Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.
Ver la página de seguridad completa de este plugin
Explorar la base de datos de CVE
Ver todos los hallazgos de seguridad