WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Simple Download Monitor?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Simple Download Monitor — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: simple-download-monitor

Estado de mantenimiento

Vulnerabilidades conocidas

15 CVEs conocidos registrados para Simple Download Monitor.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-58197 Simple Download Monitor [simple-download-monitor] < 3.9.35 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.9.35 3.9.35 2025-08-27
CVE-2025-24663 Simple Download Monitor [simple-download-monitor] < 3.9.26 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,6 < 3.9.26 3.9.26 2025-01-24
Simple Download Monitor [simple-download-monitor] < 3.9.6 Desconocido < 3.9.6 3.9.6 2023-10-05
Simple Download Monitor [simple-download-monitor] < 3.2.9 Desconocido < 3.2.9 3.2.9 2023-01-19
CVE-2021-24694 Simple Download Monitor [simple-download-monitor] < 3.9.11 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.9.11 3.9.11 2021-12-21
CVE-2021-24696 Simple Download Monitor [simple-download-monitor] < 3.9.11 Falsificación de petición en sitios cruzados (CSRF) Alta 8,8 < 3.9.11 3.9.11 2021-12-21
CVE-2021-24693 Simple Download Monitor [simple-download-monitor] < 3.9.11 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Crítica 9,0 < 3.9.11 3.9.11 2021-10-05
CVE-2021-24695 Simple Download Monitor [simple-download-monitor] < 3.9.11 Solicitud directa (Forced Browsing / navegación forzada) Alta 7,5 < 3.9.11 3.9.11 2021-10-05

CVE-2025-58197

The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-24663

The Simple Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Simple Download Monitor [simple-download-monitor] < 3.9.6

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.6). WPScanTeam discovered and reported this Broken Access Control vulnerability in WordPress Simple Download Monitor Plugin. This vulnerability has been fixed in version 3.9.6.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.2.9

Upgrade the plugin. James Golovich discovered and reported this Bypass Vulnerability vulnerability in WordPress Simple Download Monitor Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 3.2.9.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24694

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.11). apple502j discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.9.11.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24696

Update the WordPress Simple Download Monitor to the latest available version (at least 3.9.9). apple502j discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.9.9.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24693

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24695

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 15 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2021-24697 Simple Download Monitor [simple-download-monitor] < 3.9.11 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.9.11 3.9.11 2021-10-05
CVE-2021-24698 Simple Download Monitor [simple-download-monitor] < 3.9.6 Control de acceso incorrecto Media 4,3 < 3.9.6 3.9.6 2021-10-05
Simple Download Monitor [simple-download-monitor] < 3.9.6 Desconocido < 3.9.6 3.9.6 2021-10-05
Simple Download Monitor [simple-download-monitor] < 3.9.6 Desconocido < 3.9.6 3.9.6 2021-10-05
CVE-2021-24692 Simple Download Monitor [simple-download-monitor] < 3.9.5 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,5 < 3.9.5 3.9.5 2021-09-02
CVE-2020-5650 Simple Download Monitor [simple-download-monitor] < 3.8.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.8.9 3.8.9 2020-10-21
CVE-2020-5651 Simple Download Monitor [simple-download-monitor] < 3.8.9 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 8,8 < 3.8.9 3.8.9 2020-10-21
CVE-2018-5212 Simple Download Monitor [simple-download-monitor] < 3.5.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.5.4 3.5.4 2018-01-02
CVE-2018-5213 Simple Download Monitor [simple-download-monitor] < 3.5.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.5.4 3.5.4 2018-01-02
Simple Download Monitor [simple-download-monitor] < 3.2.9 Desconocido < 3.2.9 3.2.9 2016-01-19
Simple Download Monitor [simple-download-monitor] < 3.2.9 Desconocido < 3.2.9 3.2.9 2016-01-19
CVE-2025-8977 Simple Download Monitor [simple-download-monitor] < 3.9.34 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Media 6,5 < 3.9.34 3.9.34 0000-00-00
CVE-2026-2383 Simple Download Monitor [simple-download-monitor] < 4.0.6 Desconocido < 4.0.6 4.0.6 0000-00-00
Simple Download Monitor [simple-download-monitor] < 3.9.6 Desconocido < 3.9.6 3.9.6
Simple Download Monitor [simple-download-monitor] < 3.2.9 Desconocido < 3.2.9 3.2.9

CVE-2021-24697

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.5). apple502j discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.9.5.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24698

The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Simple Download Monitor [simple-download-monitor] < 3.9.6

Unauthorized Log Reset vulnerability discovered by WPScanTeam in WordPress Simple Download Monitor plugin (versions <= 3.9.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.9.6

The Simple Download Monitor plugin for WordPress is vulnerable to Log Resets in versions up to, and including, 3.9.5. This is due to a lack of nonce and capability checks on the 'sdm_reset_log' AJAX action. This makes it possible for authenticated subscriber-level attackers and above (unauthenticated if performing CSRF) to reset logs within the vulnerable service.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24692

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2020-5650

WordPress Plugin "Simple Download Monitor" provided by Tips and Tricks HQ contains multiple vulnerabilities listed below. * Cross-site Scripting (CWE-79) - CVE-2020-5650 * SQL Injection (CWE-89) - CVE-2020-5651 Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, this case was reported to IPA, and JPCERT/CC coordinated with the developer for the publication under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2020-5651

WordPress Plugin "Simple Download Monitor" provided by Tips and Tricks HQ contains multiple vulnerabilities listed below. * Cross-site Scripting (CWE-79) - CVE-2020-5650 * SQL Injection (CWE-89) - CVE-2020-5651 Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, this case was reported to IPA, and JPCERT/CC coordinated with the developer for the publication under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2018-5212

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.5.4). wpl0v3r discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2018-5213

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.5.4). wpl0v3r discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.2.9

Because of this vulnerability, any user can access the "sdm_tiny_get_post_ids" action which will return a JSON encoded list of all "post_id"and "post_title" that were uploaded with this plugin. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.2.9

The Simple Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'sdm_tiny_get_post_ids_ajax_call()' and 'sdm_remove_thumbnail_image_ajax_call()' functions in versions up to, and including, 3.2.8. This makes it possible for unauthorized attackers to access otherwise private files and delete thumbnails.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-8977

The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2383

The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Simple Download Monitor [simple-download-monitor] < 3.9.6

The sdm_reset_log AJAX action of the plugin does not have any capability and CSRF checks, which could allow any authenticated user (such as subscriber), or an attacker performing a CSRF attack against a logged in admin to reset the log entries

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Simple Download Monitor [simple-download-monitor] < 3.2.9

The Simple Download Monitor WordPress plugin was affected by an Insufficient Authorisation security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.