PoC Index

CVE-2021-24695

HIGH 7.5EPSS 1.7%

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.68% chance of exploitation in the next 30 days, 75th percentile
Published
2021-11-08
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related