Description
WordPress Plugin SS Downloads is prone to cross-site request forgery and information disclosure vulnerabilities. An attacker can exploit these issues to perform certain administrative actions and gain unauthorized access to the affected application, or to obtain sensitive information that may help in launching further attacks. WordPress Plugin SS Downloads version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Plugin St-Daily-Tip Cross-Site Request Forgery (4.7)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Cross-Site Scripting (1.1.46)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-11619)
WordPress Plugin WordPress OpenID Connect Client Cross-Site Scripting (2.1.4)