Extension WordPress
Vulnérabilités Simple Downloads List
Cette page rassemble les failles publiées pour Simple Downloads List, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Simple Downloads List
2 fiches
Simple Downloads List <= 1.4.3 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_neofix_sdl_edit' AJAX endpoint along with many others in all versions up to, and including, 1.4.3. This…
*-1.4.3
1.5.0
07/11/2025
Simple Downloads List <= 1.4.2 – Authenticated (Contributor+) SQL Injection
The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofix_sdl' shortcode in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and…
*-1.4.2
1.4.3
23/01/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.