CVE · High

CVE-2021-24695 — Simple Download Monitor [simple-download-monitor] < 3.9.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24695 Simple Download Monitor [simple-download-monitor] < 3.9.11 Direct Request ('Forced Browsing') High 7.5 < 3.9.11 3.9.11 2021-10-05

CVE-2021-24695

The Simple Download Monitor plugin before version 3.9.6 stores log files in a location that can be easily guessed by attackers, and lacks proper access controls to restrict who can retrieve these logs. This allows unauthenticated visitors to download and view the log files, which may expose sensitive data including user IP addresses and usernames.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.