CVE-2021-24698
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
Source: CVE.org
CVE · Medium
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2021-24698 | Simple Download Monitor [simple-download-monitor] < 3.9.6 | Improper Access Control | Medium 4.3 | < 3.9.6 | 3.9.6 | 2021-10-05 | — |
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
Source: CVE.org
No signup, no credit card — enter your URL and get a security report in seconds.