The Download Plugin WordPress plugin... CVE-2021-25059

- AV AC AU C I A
发布: 2022-11-28
修订: 2024-11-21

The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息