CVE Database /
CVE-2021-24696
CVE · High
CVE-2021-24696 — Simple Download Monitor [simple-download-monitor] < 3.9.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24696
|
Simple Download Monitor [simple-download-monitor] < 3.9.11 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 3.9.11
|
3.9.11 |
2021-12-21 |
—
|
CVE-2021-24696
The Simple Download Monitor plugin before version 3.9.9 contains a cross-site request forgery vulnerability that could enable an attacker to trick authenticated users with higher privileges into performing unintended actions on the website. A researcher named apple502j identified and reported this flaw. Installation of version 3.9.9 or later resolves this security issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings