plugin

Download Counter Vulnerabilities

2 known security issues reported for the Download Counter WordPress plugin. Most recent disclosed Aug 4, 2025.

1 high 1 medium

Running Download Counter on your site? Check whether your installed version is affected.

Scan your site free

Download Counter <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via name Parameter

medium

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arb...

CVSS:
6.4
Affected:
up to 1.3
Fixed in:
1.4
Disclosed:
Aug 4, 2025

CVE-2025-8294 on NVD →

Download Counter <= 1.4 - Unauthenticated Arbitrary File Read

high

The Download Counter plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.4. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 1.4
Fix:
No patched version reported
Disclosed:
Jun 22, 2025

CVE-2025-60242 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database