CVE · High

CVE-2021-24696 — Simple Download Monitor [simple-download-monitor] < 3.9.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24696 Simple Download Monitor [simple-download-monitor] < 3.9.11 Cross-Site Request Forgery (CSRF) High 8.8 < 3.9.11 3.9.11 2021-12-21

CVE-2021-24696

The Simple Download Monitor plugin before version 3.9.9 contains a cross-site request forgery vulnerability that could enable an attacker to trick authenticated users with higher privileges into performing unintended actions on the website. A researcher named apple502j identified and reported this flaw. Installation of version 3.9.9 or later resolves this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.