PT-2021-16200 · WordPress · Simple Download Monitor

Apple502J

·

Published

2021-11-08

·

Updated

2022-11-09

·

CVE-2021-24695

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple Download Monitor WordPress plugin versions prior to 3.9.6
Description The issue allows unauthenticated users to download and read logs containing sensitive information, such as IP addresses and usernames, due to the logs being saved in a predictable location without any authentication or authorization in place.
Recommendations For versions prior to 3.9.6, update to version 3.9.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the log files to prevent unauthenticated users from downloading and reading them.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-24695

Affected Products

Simple Download Monitor