CVE · Medium

CVE-2018-5212 — Simple Download Monitor [simple-download-monitor] < 3.5.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-5212, CVE-2018-5213 Simple Download Monitor [simple-download-monitor] < 3.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.4 3.5.4 2018-01-02

CVE-2018-5212, CVE-2018-5213

The Simple Download Monitor plugin contained a cross-site scripting vulnerability in versions before 3.5.4 that could enable an attacker to inject malicious scripts into a website, potentially executing redirects, advertisements, or other HTML code when visitors access the site. This flaw was identified by wpl0v3r and has been patched in version 3.5.4 and later. Users should upgrade to the fixed version to protect against this attack vector.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.