SQL Injection Vulnerability in Simple Download Monitor by WordPress
CVE-2020-5651

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 October 2020

What is CVE-2020-5651?

An SQL injection vulnerability exists in Simple Download Monitor versions 3.8.8 and earlier, allowing remote attackers to execute arbitrary SQL commands. This flaw can be exploited through specially crafted URLs, posing significant risks to data integrity and application security. Users of affected versions should take immediate action to mitigate potential exploitation.

Affected Version(s)

Simple Download Monitor 3.8.8 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.