CVE-2020-5651
The Simple Download Monitor WordPress plugin before version 3.8.9 contains a SQL injection vulnerability that allows attackers to execute arbitrary SQL queries. This flaw exists in the plugin's handling of user-supplied input, which is not properly sanitized before being used in database operations. The vulnerability could allow an attacker to extract sensitive data, modify database contents, or potentially gain unauthorized access to the WordPress installation. The issue was reported by Gen Sato of Mitsui Bussan Secure Directions, Inc. and coordinated through the Information Security Early Warning Partnership.
Based on public CVE data (MITRE/NVD).