CVE-2025-58197
The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-24663
The Simple Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24694
Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.11).
apple502j discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.9.11.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-24693
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 15 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2021-24697
|
Simple Download Monitor [simple-download-monitor] < 3.9.11 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.9.11
|
3.9.11 |
2021-10-05 |
—
|
|
CVE-2021-24698
|
Simple Download Monitor [simple-download-monitor] < 3.9.6 |
Control de acceso incorrecto |
Media
4,3
|
< 3.9.6
|
3.9.6 |
2021-10-05 |
—
|
|
—
|
Simple Download Monitor [simple-download-monitor] < 3.9.6 |
— |
Desconocido
|
< 3.9.6
|
3.9.6 |
2021-10-05 |
—
|
|
—
|
Simple Download Monitor [simple-download-monitor] < 3.9.6 |
— |
Desconocido
|
< 3.9.6
|
3.9.6 |
2021-10-05 |
—
|
|
CVE-2021-24692
|
Simple Download Monitor [simple-download-monitor] < 3.9.5 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Media
6,5
|
< 3.9.5
|
3.9.5 |
2021-09-02 |
—
|
|
CVE-2020-5650
|
Simple Download Monitor [simple-download-monitor] < 3.8.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.8.9
|
3.8.9 |
2020-10-21 |
—
|
|
CVE-2020-5651
|
Simple Download Monitor [simple-download-monitor] < 3.8.9 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
8,8
|
< 3.8.9
|
3.8.9 |
2020-10-21 |
—
|
|
CVE-2018-5212
|
Simple Download Monitor [simple-download-monitor] < 3.5.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.4
|
3.5.4 |
2018-01-02 |
—
|
|
CVE-2018-5213
|
Simple Download Monitor [simple-download-monitor] < 3.5.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.4
|
3.5.4 |
2018-01-02 |
—
|
|
—
|
Simple Download Monitor [simple-download-monitor] < 3.2.9 |
— |
Desconocido
|
< 3.2.9
|
3.2.9 |
2016-01-19 |
—
|
|
—
|
Simple Download Monitor [simple-download-monitor] < 3.2.9 |
— |
Desconocido
|
< 3.2.9
|
3.2.9 |
2016-01-19 |
—
|
|
CVE-2025-8977
|
Simple Download Monitor [simple-download-monitor] < 3.9.34 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Media
6,5
|
< 3.9.34
|
3.9.34 |
0000-00-00 |
—
|
|
CVE-2026-2383
|
Simple Download Monitor [simple-download-monitor] < 4.0.6 |
— |
Desconocido
|
< 4.0.6
|
4.0.6 |
0000-00-00 |
—
|
|
—
|
Simple Download Monitor [simple-download-monitor] < 3.9.6 |
— |
Desconocido
|
< 3.9.6
|
3.9.6 |
— |
—
|
|
—
|
Simple Download Monitor [simple-download-monitor] < 3.2.9 |
— |
Desconocido
|
< 3.2.9
|
3.2.9 |
— |
—
|
CVE-2021-24697
Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.5).
apple502j discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.9.5.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-24698
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Simple Download Monitor [simple-download-monitor] < 3.9.6
Unauthorized Log Reset vulnerability discovered by WPScanTeam in WordPress Simple Download Monitor plugin (versions <= 3.9.5).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Simple Download Monitor [simple-download-monitor] < 3.9.6
The Simple Download Monitor plugin for WordPress is vulnerable to Log Resets in versions up to, and including, 3.9.5. This is due to a lack of nonce and capability checks on the 'sdm_reset_log' AJAX action. This makes it possible for authenticated subscriber-level attackers and above (unauthenticated if performing CSRF) to reset logs within the vulnerable service.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24692
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2020-5650
WordPress Plugin "Simple Download Monitor" provided by Tips and Tricks HQ contains multiple vulnerabilities listed below. * Cross-site Scripting (CWE-79) - CVE-2020-5650 * SQL Injection (CWE-89) - CVE-2020-5651 Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, this case was reported to IPA, and JPCERT/CC coordinated with the developer for the publication under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
CVE-2020-5651
WordPress Plugin "Simple Download Monitor" provided by Tips and Tricks HQ contains multiple vulnerabilities listed below. * Cross-site Scripting (CWE-79) - CVE-2020-5650 * SQL Injection (CWE-89) - CVE-2020-5651 Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, this case was reported to IPA, and JPCERT/CC coordinated with the developer for the publication under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
CVE-2018-5212
Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.5.4).
wpl0v3r discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.4.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2018-5213
Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.5.4).
wpl0v3r discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.4.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Simple Download Monitor [simple-download-monitor] < 3.2.9
Because of this vulnerability, any user can access the "sdm_tiny_get_post_ids" action which will return a JSON encoded list of all "post_id"and "post_title" that were uploaded with this plugin.
Upgrade the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Simple Download Monitor [simple-download-monitor] < 3.2.9
The Simple Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'sdm_tiny_get_post_ids_ajax_call()' and 'sdm_remove_thumbnail_image_ajax_call()' functions in versions up to, and including, 3.2.8. This makes it possible for unauthorized attackers to access otherwise private files and delete thumbnails.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-8977
The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2383
The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Simple Download Monitor [simple-download-monitor] < 3.9.6
The sdm_reset_log AJAX action of the plugin does not have any capability and CSRF checks, which could allow any authenticated user (such as subscriber), or an attacker performing a CSRF attack against a logged in admin to reset the log entries
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Simple Download Monitor [simple-download-monitor] < 3.2.9
The Simple Download Monitor WordPress plugin was affected by an Insufficient Authorisation security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.