WP Clinic
Log in Sign up

CVE · Medium

CVE-2021-24698 — Simple Download Monitor [simple-download-monitor] < 3.9.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24698 Simple Download Monitor [simple-download-monitor] < 3.9.6 Improper Access Control Medium 4.3 < 3.9.6 3.9.6 2021-10-05

CVE-2021-24698

The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.