Simple Download Monitor - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field vulnerability
medium
Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field vulnerability
- CVSS:
- 6.5
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.6
- Disclosed:
- Feb 26, 2026
Simple Download Monitor <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field
medium
The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject ar...
- CVSS:
- 6.4
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.6
- Disclosed:
- Feb 26, 2026
CVE-2026-2383 on NVD →
Simple Download Monitor <= 3.9.33 - Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality
medium
The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentica...
- CVSS:
- 6.5
- Affected:
- up to 3.9.33
- Fixed in:
- 3.9.34
- Disclosed:
- Aug 27, 2025
CVE-2025-8977 on NVD →
Simple Download Monitor <= 3.9.34 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 3.9.34
- Fixed in:
- 3.9.35
- Disclosed:
- Aug 27, 2025
CVE-2025-58197 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.35
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mra13 / Team Tips and Tricks HQ Simple Download Monitor allows Stored XSS. This issue affects Simple Download Monitor: from n/a through 3.9.34.
- Affected:
- up to 3.9.35
- Fixed in:
- 3.9.35
- Disclosed:
- Aug 27, 2025
CVE-2025-58197 on NVD →
Simple Download Monitor <= 3.9.25 - Authenticated (Administrator+) SQL Injection
medium
The Simple Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level...
- CVSS:
- 4.9
- Affected:
- up to 3.9.25
- Fixed in:
- 3.9.26
- Disclosed:
- Jan 24, 2025
CVE-2025-24663 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.26 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Ruhul Amin, Josh Lobe Simple Download Monitor allows Blind SQL Injection. This issue affects Simple Download Monitor: from n/a through 3.9.25.
- Affected:
- up to 3.9.26
- Fixed in:
- 3.9.26
- Disclosed:
- Jan 24, 2025
CVE-2025-24663 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.6 (closed)
unknown
Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.6).
apple502j discovered and reported this Broken Access Control vulnerability in WordPress Simple Download Monitor Plugin. This vulnerability has been fixed in version 3.9.6.
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Oct 5, 2023
Simple Download Monitor [simple-download-monitor] < 3.9.6 (closed)
unknown
Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.6).
WPScanTeam discovered and reported this Broken Access Control vulnerability in WordPress Simple Download Monitor Plugin. This vulnerability has been fixed in version 3.9.6.
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Oct 5, 2023
Simple Download Monitor [simple-download-monitor] < 3.2.9 (closed)
unknown
Upgrade the plugin.
James Golovich discovered and reported this Bypass Vulnerability vulnerability in WordPress Simple Download Monitor Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 3.2.9.
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
- Disclosed:
- Jan 19, 2023
Simple Download Monitor [simple-download-monitor] < 3.9.5 (closed)
unknown
[en] The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5
- Disclosed:
- Mar 14, 2022
CVE-2021-24692 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.11 (closed)
unknown
[en] The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Jan 24, 2022
CVE-2021-24694 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.11 (closed)
unknown
[en] The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Jan 24, 2022
CVE-2021-24696 on NVD →
Simple Download Monitor <= 3.9.8 - Multiple Cross-Site Request Forgery vulnerabilities
high
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
- CVSS:
- 8.8
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.9
- Disclosed:
- Dec 21, 2021
CVE-2021-24696 on NVD →
Simple Download Monitor <= 3.9.10 - Contributor+ Stored Cross-Site Scripting via Shortcodes
medium
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.
- CVSS:
- 5.4
- Affected:
- up to 3.9.10
- Fixed in:
- 3.9.11
- Disclosed:
- Dec 21, 2021
CVE-2021-24694 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.11 (closed)
unknown
[en] The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a revie...
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Nov 8, 2021
CVE-2021-24693 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.11 (closed)
unknown
[en] The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Nov 8, 2021
CVE-2021-24695 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.11 (closed)
unknown
[en] The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Nov 8, 2021
CVE-2021-24697 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.6 (closed)
unknown
[en] The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Nov 8, 2021
CVE-2021-24698 on NVD →
Simple Download Monitor <= 3.9.4 - Contributor+ Stored Cross-Site Scripting via File Thumbnail
critical
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review sta...
- CVSS:
- 9
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- Oct 5, 2021
CVE-2021-24693 on NVD →
Simple Download Monitor <= 3.9.4 - Reflected Cross-Site Scripting
medium
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5
- Disclosed:
- Oct 5, 2021
CVE-2021-24697 on NVD →
Simple Download Monitor <= 3.9.5 - Sensitive Data Exposure
medium
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
- CVSS:
- 5.3
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Oct 5, 2021
CVE-2021-24695 on NVD →
Simple Download Monitor <= 3.9.5 - Log Reset
medium
The Simple Download Monitor plugin for WordPress is vulnerable to Log Resets in versions up to, and including, 3.9.5. This is due to a lack of nonce and capability checks on the 'sdm_reset_log' AJAX action. This makes it possible for authenticated subscriber-level attackers and above (unauthenticated if performing CSRF...
- CVSS:
- 4.3
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Oct 5, 2021
Simple Download Monitor <= 3.9.5 - Contributor+ Arbitrary Thumbnail Removal
medium
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
- CVSS:
- 4.3
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Oct 5, 2021
CVE-2021-24698 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.9.6 (closed)
unknown
The Simple Download Monitor plugin for WordPress is vulnerable to Log Resets in versions up to, and including, 3.9.5. This is due to a lack of nonce and capability checks on the 'sdm_reset_log' AJAX action. This makes it possible for authenticated subscriber-level attackers and above (unauthenticated if performing CSRF...
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Oct 5, 2021
Simple Download Monitor [simple-download-monitor] < 3.9.6 (closed)
unknown
Unauthorized Log Reset vulnerability discovered by WPScanTeam in WordPress Simple Download Monitor plugin (versions <= 3.9.5).
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Oct 5, 2021
Simple Download Monitor <= 3.9.4 - Contributor+ Arbitrary File Download
medium
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
- CVSS:
- 6.5
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5
- Disclosed:
- Sep 2, 2021
CVE-2021-24692 on NVD →
Simple Download Monitor <= 3.8.8 - SQL Injection
high
The Simple Download Monitor plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries...
- CVSS:
- 8.8
- Affected:
- up to 3.8.8
- Fixed in:
- 3.8.9
- Disclosed:
- Oct 21, 2020
CVE-2020-5651 on NVD →
Simple Download Monitor <= 3.8.8 - Unauthenticated Stored Cross-Site Scripting
medium
The Simple Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping on the User-Agent header. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.9
- Disclosed:
- Oct 21, 2020
CVE-2020-5650 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.8.9 (closed)
unknown
[en] SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
- Affected:
- up to 3.8.9
- Fixed in:
- 3.8.9
- Disclosed:
- Oct 21, 2020
CVE-2020-5651 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.8.9 (closed)
unknown
[en] Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
- Affected:
- up to 3.8.9
- Fixed in:
- 3.8.9
- Disclosed:
- Oct 21, 2020
CVE-2020-5650 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.5.4 (closed)
unknown
[en] The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
- Disclosed:
- Jan 4, 2018
CVE-2018-5213 on NVD →
Simple Download Monitor [simple-download-monitor] < 3.5.4 (closed)
unknown
[en] The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
- Disclosed:
- Jan 4, 2018
CVE-2018-5212 on NVD →
Simple Download Monitor < 3.5.4 - Authenticated Stored Cross-Site Scripting
medium
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
- CVSS:
- 6.4
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
- Disclosed:
- Jan 2, 2018
CVE-2018-5212 on NVD →
Simple Download Monitor < 3.5.4 - Authenticated Stored Cross-Site Scripting
medium
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
- CVSS:
- 5.4
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4
- Disclosed:
- Jan 2, 2018
CVE-2018-5213 on NVD →
Simple Download Monitor <= 3.2.8 - Missing Authorization
critical
The Simple Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'sdm_tiny_get_post_ids_ajax_call()' and 'sdm_remove_thumbnail_image_ajax_call()' functions in versions up to, and including, 3.2.8. This makes it possible for unauthorized attackers to access o...
- CVSS:
- 9.9
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.9
- Disclosed:
- Jan 19, 2016
Simple Download Monitor [simple-download-monitor] < 3.2.9 (closed)
unknown
Because of this vulnerability, any user can access the "sdm_tiny_get_post_ids" action which will return a JSON encoded list of all "post_id"and "post_title" that were uploaded with this plugin.
Upgrade the plugin.
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
- Disclosed:
- Jan 19, 2016
Simple Download Monitor [simple-download-monitor] < 3.2.9 (closed)
unknown
The Simple Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'sdm_tiny_get_post_ids_ajax_call()' and 'sdm_remove_thumbnail_image_ajax_call()' functions in versions up to, and including, 3.2.8. This makes it possible for unauthorized attackers to access o...
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
- Disclosed:
- Jan 19, 2016
Simple Download Monitor [simple-download-monitor] < 3.2.9 (closed)
unknown
The Simple Download Monitor WordPress plugin was affected by an Insufficient Authorisation security vulnerability.
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
Simple Download Monitor [simple-download-monitor] < 3.9.6 (closed)
unknown
The sdm_reset_log AJAX action of the plugin does not have any capability and CSRF checks, which could allow any authenticated user (such as subscriber), or an attacker performing a CSRF attack against a logged in admin to reset the log entries
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
Simple Download Monitor [simple-download-monitor] < 3.9.34
unknown
- Affected:
- up to 3.9.34
- Fixed in:
- 3.9.34
CVE-2025-8977 on NVD →