WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Simple Download Monitor safe?

Easily manage downloadable files and monitor downloads of your digital files from your WordPress site.

What this plugin does

  • Slug: simple-download-monitor
  • Author: mra13 / Team Tips and Tricks HQ
  • 20000+ active installs
  • 94/100 rating (155 reviews on wordpress.org)
  • 1346170 all-time downloads
  • On WordPress.org since 2009-10-28

countCounterdownloaddownloadstracker

Maintenance status

  • Last updated: 2026-07-21 8:07am GMT
  • Tested up to WordPress: 7.0.2

Known vulnerabilities

15 known CVEs on file for Simple Download Monitor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-58197 Simple Download Monitor [simple-download-monitor] < 3.9.35 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.9.35 3.9.35 2025-08-27
CVE-2025-24663 Simple Download Monitor [simple-download-monitor] < 3.9.26 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 3.9.26 3.9.26 2025-01-24
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6 2023-10-05
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9 2023-01-19
CVE-2021-24694 Simple Download Monitor [simple-download-monitor] < 3.9.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.9.11 3.9.11 2021-12-21
CVE-2021-24696 Simple Download Monitor [simple-download-monitor] < 3.9.11 Cross-Site Request Forgery (CSRF) High 8.8 < 3.9.11 3.9.11 2021-12-21
CVE-2021-24693 Simple Download Monitor [simple-download-monitor] < 3.9.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Critical 9.0 < 3.9.11 3.9.11 2021-10-05
CVE-2021-24695 Simple Download Monitor [simple-download-monitor] < 3.9.11 Direct Request ('Forced Browsing') High 7.5 < 3.9.11 3.9.11 2021-10-05

CVE-2025-58197

The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-24663

The Simple Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

Simple Download Monitor [simple-download-monitor] < 3.9.6

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.6). WPScanTeam discovered and reported this Broken Access Control vulnerability in WordPress Simple Download Monitor Plugin. This vulnerability has been fixed in version 3.9.6.

Source: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.2.9

Upgrade the plugin. James Golovich discovered and reported this Bypass Vulnerability vulnerability in WordPress Simple Download Monitor Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 3.2.9.

Source: Patchstack

CVE-2021-24694

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.11). apple502j discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.9.11.

Source: Patchstack

CVE-2021-24696

Update the WordPress Simple Download Monitor to the latest available version (at least 3.9.9). apple502j discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.9.9.

Source: Patchstack

CVE-2021-24693

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin

Source: CVE.org

CVE-2021-24695

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

Source: CVE.org

+ 15 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24697 Simple Download Monitor [simple-download-monitor] < 3.9.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.9.11 3.9.11 2021-10-05
CVE-2021-24698 Simple Download Monitor [simple-download-monitor] < 3.9.6 Improper Access Control Medium 4.3 < 3.9.6 3.9.6 2021-10-05
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6 2021-10-05
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6 2021-10-05
CVE-2021-24692 Simple Download Monitor [simple-download-monitor] < 3.9.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 3.9.5 3.9.5 2021-09-02
CVE-2020-5650 Simple Download Monitor [simple-download-monitor] < 3.8.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.8.9 3.8.9 2020-10-21
CVE-2020-5651 Simple Download Monitor [simple-download-monitor] < 3.8.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 3.8.9 3.8.9 2020-10-21
CVE-2018-5212 Simple Download Monitor [simple-download-monitor] < 3.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.4 3.5.4 2018-01-02
CVE-2018-5213 Simple Download Monitor [simple-download-monitor] < 3.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.4 3.5.4 2018-01-02
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9 2016-01-19
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9 2016-01-19
CVE-2025-8977 Simple Download Monitor [simple-download-monitor] < 3.9.34 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 3.9.34 3.9.34 0000-00-00
CVE-2026-2383 Simple Download Monitor [simple-download-monitor] < 4.0.6 Unknown < 4.0.6 4.0.6 0000-00-00
Simple Download Monitor [simple-download-monitor] < 3.9.6 Unknown < 3.9.6 3.9.6
Simple Download Monitor [simple-download-monitor] < 3.2.9 Unknown < 3.2.9 3.2.9

CVE-2021-24697

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.9.5). apple502j discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.9.5.

Source: Patchstack

CVE-2021-24698

The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.

Source: CVE.org

Simple Download Monitor [simple-download-monitor] < 3.9.6

Unauthorized Log Reset vulnerability discovered by WPScanTeam in WordPress Simple Download Monitor plugin (versions <= 3.9.5).

Source: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.9.6

The Simple Download Monitor plugin for WordPress is vulnerable to Log Resets in versions up to, and including, 3.9.5. This is due to a lack of nonce and capability checks on the 'sdm_reset_log' AJAX action. This makes it possible for authenticated subscriber-level attackers and above (unauthenticated if performing CSRF) to reset logs within the vulnerable service.

Source: Wordfence

CVE-2021-24692

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

Source: CVE.org

CVE-2020-5650

WordPress Plugin "Simple Download Monitor" provided by Tips and Tricks HQ contains multiple vulnerabilities listed below. * Cross-site Scripting (CWE-79) - CVE-2020-5650 * SQL Injection (CWE-89) - CVE-2020-5651 Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, this case was reported to IPA, and JPCERT/CC coordinated with the developer for the publication under Information Security Early Warning Partnership.

Source: jvndb.jvn.jp

CVE-2020-5651

WordPress Plugin "Simple Download Monitor" provided by Tips and Tricks HQ contains multiple vulnerabilities listed below. * Cross-site Scripting (CWE-79) - CVE-2020-5650 * SQL Injection (CWE-89) - CVE-2020-5651 Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated on his own. After coordination was completed, this case was reported to IPA, and JPCERT/CC coordinated with the developer for the publication under Information Security Early Warning Partnership.

Source: jvndb.jvn.jp

CVE-2018-5212

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.5.4). wpl0v3r discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.4.

Source: Patchstack

CVE-2018-5213

Update the WordPress Simple Download Monitor plugin to the latest available version (at least 3.5.4). wpl0v3r discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Download Monitor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.4.

Source: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.2.9

Because of this vulnerability, any user can access the "sdm_tiny_get_post_ids" action which will return a JSON encoded list of all "post_id"and "post_title" that were uploaded with this plugin. Upgrade the plugin.

Source: Patchstack

Simple Download Monitor [simple-download-monitor] < 3.2.9

The Simple Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'sdm_tiny_get_post_ids_ajax_call()' and 'sdm_remove_thumbnail_image_ajax_call()' functions in versions up to, and including, 3.2.8. This makes it possible for unauthorized attackers to access otherwise private files and delete thumbnails.

Source: Wordfence

CVE-2025-8977

The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

CVE-2026-2383

The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

Simple Download Monitor [simple-download-monitor] < 3.9.6

The sdm_reset_log AJAX action of the plugin does not have any capability and CSRF checks, which could allow any authenticated user (such as subscriber), or an attacker performing a CSRF attack against a logged in admin to reset the log entries

Source: WPScan

Simple Download Monitor [simple-download-monitor] < 3.2.9

The Simple Download Monitor WordPress plugin was affected by an Insufficient Authorisation security vulnerability.

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.