Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-25059


The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.


Published

2022-11-28T14:15:10.663

Last Modified

2025-04-25T15:15:29.763

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses

-


Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application metagauss download_plugin < 2.0.0 Yes

References