Extension WordPress

Vulnérabilités Simple Download Counter

Cette page rassemble les failles publiées pour Simple Download Counter, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Simple Download Counter

5 fiches

CVE-2026-4278 Moyenne · 6,4
Simple Download Counter

Simple Download Counter <= 2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Shortcode Attribute

The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode…

Versions affectées

*-2.3

Correctif

2.3.1

Publication

25/03/2026

CVE-2025-13677 Moyenne · 4,9
Simple Download Counter

Simple Download Counter <= 2.2.2 – Authenticated (Administrator+) Arbitrary File Read via Path Traversal

The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient path validation in the `simple_download_counter_parse_path()` function. This makes it possible for authenticated attackers,…

Versions affectées

*-2.2.2

Correctif

2.2.3

Publication

09/12/2025

CVE-2025-46240 Moyenne · 6,4
Simple Download Counter

Simple Download Counter <= 2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-2.2

Correctif

2.2.1

Publication

22/04/2025

CVE-2025-1730 Moyenne · 6,5
Simple Download Counter

Simple Download Counter <= 2.0 – Authenticated (Author+) Arbitrary File Read

The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This makes it possible for authenticated attackers, with Author-level access and above, to extract…

Versions affectées

*-2.0

Correctif

2.1

Publication

28/02/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités