The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.
2022-11-28T14:15:10.663
2025-04-25T15:15:29.763
Modified
CVSSv3.1: 4.3 (MEDIUM)
-
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | metagauss | download_plugin | < 2.0.0 | Yes |