CVE · High

CVE-2025-24663 — Simple Download Monitor [simple-download-monitor] < 3.9.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24663 Simple Download Monitor [simple-download-monitor] < 3.9.26 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 3.9.26 3.9.26 2025-01-24

CVE-2025-24663

The Simple Download Monitor plugin for WordPress contains a security flaw in versions up to 3.9.25, which allows malicious users with elevated privileges to inject unauthorized SQL code into database queries. This vulnerability arises from inadequate handling of user-input data and insufficient modification of existing SQL statements. As a result, attackers can potentially extract sensitive information from the database by appending additional SQL queries to existing ones.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.