4.3
CVSSv3

CVE-2021-25059

Published: 28/11/2022 Updated: 30/11/2022
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8

Vulnerability Summary

The Download Plugin WordPress plugin prior to 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

metagauss download plugin

Github Repositories

CVE-2021-25059 The Download Plugin WordPress plugin before 200 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website authentication complexity vector not available not available not available confid