N/A
2026-03-25< 2.3.1
Simple Download Counter <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Shortcode Attribute
Minimum safe version
2.3.1
Update to 2.3.1 or later to address 5 fixable vulnerabilities
Simple Download Counter <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Shortcode Attribute
CVE-2025-13677
CVE-2025-46240
WordPress Simple Download Counter Plugin <= 2.0 is vulnerable to Arbitrary File Download
WordPress Simple Download Counter Plugin <= 1.6 is vulnerable to Cross Site Scripting (XSS)