← back
CVE-2021-24703CWE-732

Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.