mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-02 07:51:39 +02:00
905 B
905 B
CVE-2021-24692
Description
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
POC
Reference
- https://wpscan.com/vulnerability/4c9fe97e-3d9b-4079-88d9-34e2d0605215
- https://wpscan.com/vulnerability/4c9fe97e-3d9b-4079-88d9-34e2d0605215
Github
No PoCs found on GitHub currently.