Simple Download Monitor <= 3.9.5 - Log Reset

2021-10-05 00:00
WPScanTeam

Strategic Overview

Status
Patched in 3.9.6
Affected Version<= 3.9.5
CVSS4.3Medium
CVEN/A
View all Simple Download Monitor vulnerabilities

Vulnerability Overview

The Simple Download Monitor plugin for WordPress is vulnerable to Log Resets in versions up to, and including, 3.9.5. This is due to a lack of nonce and capability checks on the 'sdm_reset_log' AJAX action. This makes it possible for authenticated subscriber-level attackers and above (unauthenticated if performing CSRF) to reset logs within the vulnerable service.

Technical Analysis

REMEDIATION: Update to version 3.9.6, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C