Simple Download Monitor <= 3.9.8 - Multiple Cross-Site Request Forgery vulnerabilities
2021-12-21 00:00
apple502jStrategic Overview
StatusPatched in 3.9.9
Affected PluginSimple Download Monitor
Affected Version
<= 3.9.8CVSS8.8High
CVE
CVE-2021-24696Vulnerability Overview
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
Technical Analysis
REMEDIATION: Update to version 3.9.9, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C