WP Clinic
Log in Sign up

CVE · High

CVE-2021-24695 — Simple Download Monitor [simple-download-monitor] < 3.9.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24695 Simple Download Monitor [simple-download-monitor] < 3.9.11 Direct Request ('Forced Browsing') High 7.5 < 3.9.11 3.9.11 2021-10-05

CVE-2021-24695

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.