Simple Download Monitor <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field
Simple Download Monitor
Minimum safe version
4.0.6
Update to 4.0.6 or later to address 24 fixable vulnerabilities
Simple Download Monitor <= 3.9.33 - Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality
CVE-2025-58197
CVE-2025-24663
Simple Download Monitor <= 3.2.8 - Insufficient Authorisation
Simple Download Monitor < 3.9.6 - Unauthorised Log Reset
WordPress Simple Download Monitor Plugin <= 3.9.5 is vulnerable to Broken Access Control
WordPress Simple Download Monitor Plugin <= 3.9.5 is vulnerable to Broken Access Control
WordPress Simple Download Monitor Plugin <= 3.2.8 is vulnerable to Bypass Vulnerability
Simple Download Monitor <= 3.2.8 - Missing Authorization
Simple Download Monitor <= 3.9.5 - Log Reset
WordPress Simple Download Monitor Plugin <= 3.2.8 - Insufficient Authorisation
WordPress Simple Download Monitor plugin <= 3.9.5 - Unauthorized Log Reset vulnerability
WordPress Simple Download Monitor Plugin <= 3.5.3 is vulnerable to Cross Site Scripting (XSS)
WordPress Simple Download Monitor Plugin <= 3.5.3 is vulnerable to Cross Site Scripting (XSS)
WordPress Simple Download Monitor Plugin <= 3.8.8 is vulnerable to SQL Injection
WordPress Simple Download Monitor Plugin <= 3.8.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2021-24698
WordPress Simple Download Monitor Plugin <= 3.9.4 is vulnerable to Cross Site Scripting (XSS)
WordPress Simple Download Monitor Plugin <= 3.9.5.1 is vulnerable to Sensitive Data Exposure
WordPress Simple Download Monitor Plugin <= 3.9.5.1 is vulnerable to Cross Site Scripting (XSS)
WordPress Simple Download Monitor Plugin <= 3.9.8 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Simple Download Monitor Plugin <= 3.9.10 is vulnerable to Cross Site Scripting (XSS)
CVE-2021-24692