PLUGIN SECURITY

Is Simple Download Monitor safe?

Easily manage downloadable files and monitor downloads of your digital files from your WordPress site.

What this plugin does

  • Slug: simple-download-monitor
  • Author: mra13 / Team Tips and Tricks HQ
  • 20000+ active installs
  • 94/100 rating (156 reviews on wordpress.org)
  • 1379214 all-time downloads
  • On WordPress.org since 2009-10-28

countCounterdownloaddownloadstracker

Maintenance status

  • Latest known version: 4.0.9
  • Last updated: 2026-08-14 6:43am GMT
  • Tested up to WordPress: 7.1
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

15 known CVEs on file for Simple Download Monitor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-58197 Simple Download Monitor [simple-download-monitor] < 3.9.35 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.9.35 3.9.35 2025-08-27 ✓ fixed in latest
CVE-2025-24663 Simple Download Monitor [simple-download-monitor] < 3.9.26 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 3.9.26 3.9.26 2025-01-24 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6 2023-10-05 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9 2023-01-19 ✓ fixed in latest
CVE-2021-24694 Simple Download Monitor [simple-download-monitor] < 3.9.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.9.11 3.9.11 2021-12-21 ✓ fixed in latest
CVE-2021-24696 Simple Download Monitor [simple-download-monitor] < 3.9.11 Cross-Site Request Forgery (CSRF) High 8.8 < 3.9.11 3.9.11 2021-12-21 ✓ fixed in latest
CVE-2021-24693 Simple Download Monitor [simple-download-monitor] < 3.9.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Critical 9.0 < 3.9.11 3.9.11 2021-10-05 ✓ fixed in latest
CVE-2021-24695 Simple Download Monitor [simple-download-monitor] < 3.9.11 Direct Request ('Forced Browsing') High 7.5 < 3.9.11 3.9.11 2021-10-05 ✓ fixed in latest
+ 19 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24697 Simple Download Monitor [simple-download-monitor] < 3.9.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.9.11 3.9.11 2021-10-05 ✓ fixed in latest
CVE-2021-24698 Simple Download Monitor [simple-download-monitor] < 3.9.6 Improper Access Control Medium 4.3 < 3.9.6 3.9.6 2021-10-05 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6 2021-10-05 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6 2021-10-05 ✓ fixed in latest
CVE-2021-24692 Simple Download Monitor [simple-download-monitor] < 3.9.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 3.9.5 3.9.5 2021-09-02 ✓ fixed in latest
CVE-2020-5650 Simple Download Monitor [simple-download-monitor] < 3.8.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.8.9 3.8.9 2020-10-21 ✓ fixed in latest
CVE-2020-5651 Simple Download Monitor [simple-download-monitor] < 3.8.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 3.8.9 3.8.9 2020-10-21 ✓ fixed in latest
CVE-2018-5212, CVE-2018-5213 Simple Download Monitor [simple-download-monitor] < 3.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.4 3.5.4 2018-01-02 ✓ fixed in latest
CVE-2018-5213 Simple Download Monitor [simple-download-monitor] < 3.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.4 3.5.4 2018-01-02 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9 2016-01-19 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9 2016-01-19 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.9.34 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 3.9.34 3.9.34 0000-00-00 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 4.0.6 Unknown < 4.0.6 4.0.6 0000-00-00 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6 ✓ fixed in latest
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9 ✓ fixed in latest
Simple Download Monitor <= 3.2.8 - Insufficient Authorisation Unknown < 3.2.9 3.2.9 ✓ fixed in latest
Simple Download Monitor < 3.9.6 - Unauthorised Log Reset Unknown < 3.9.6 3.9.6 ✓ fixed in latest
CVE-2025-8977 Simple Download Monitor < 3.9.34 - Simple Download Monitor < 3.9.34 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality Unknown < 3.9.34 3.9.34 ✓ fixed in latest
CVE-2026-2383 Simple Download Monitor < 4.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field Unknown < 4.0.6 4.0.6 ✓ fixed in latest

How to fix it

Keep Simple Download Monitor updated — 4.0.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.