Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Metagauss Subscribe
Filtered by product Download Plugin
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25059 1 Metagauss 1 Download Plugin 2022-11-30 N/A 4.3 MEDIUM
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.
CVE-2021-24703 1 Metagauss 1 Download Plugin 2022-10-24 3.5 LOW 5.7 MEDIUM
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.