CVE-2021-24703
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
- Affected products
- Download Plugin
- Metagauss Download Plugin
- < 1.6.1
- Fix
- Available
- CVSS 3.1
- 5.7 MEDIUM
- EPSS
- 0.4% (32th percentile)
- Weakness
- CWE-352, CWE-732
- NVD status
- Modified
- Published
- 2021-11-23
CVE-2021-24703 at NVD
1 known exploit for CVE-2021-24703
Proof-of-concept code and exploit modules indexed by Sploitus