Description
WordPress Plugin SS Downloads is prone to cross-site request forgery and information disclosure vulnerabilities. An attacker can exploit these issues to perform certain administrative actions and gain unauthorized access to the affected application, or to obtain sensitive information that may help in launching further attacks. WordPress Plugin SS Downloads version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop 'uploadfilexd.php' Arbitrary File Upload (2.4.3)
Liferay Portal Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-26265)
WordPress Plugin Gallery-Photo Albums-Portfolio Cross-Site Scripting (1.3.47)
WordPress Plugin CodeArt-Google MP3 Player Arbitrary File Disclosure (1.0.11)
WordPress Plugin Caldera Forms-More Than Contact Forms Cross-Site Scripting (1.4.1)