Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Simple Download Monitor — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Simple Download Monitor, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known weaknesses in Simple Download Monitor, a WordPress plugin categorized under the weakness type of insecure direct object references or improper access control depending on the specific flaw. The content aggregates security advisories and vulnerability reports associated with this specific product, covering incidents discovered and reported between 2019 and the present day. By organizing these records chronologically and by severity, the database aims to provide a clear historical context for developers, security researchers, and site administrators who rely on this tool. Users can track the vendor's response timeline and the publication history of security patches for Simple Download Monitor. Furthermore, this aggregation allows for a deeper understanding of common vulnerability classes affecting WordPress plugins, particularly those related to file access and user permission bypasses. You can also look up the full vulnerability history of the product to identify patterns in how bugs were introduced and subsequently fixed over multiple versions. This resource serves as a neutral reference point for assessing the long-term security posture of the plugin without promotional bias. It is designed to help you make informed decisions about whether to update, replace, or continue using the software based on empirical security data. The information presented here is derived from public disclosures and vendor notifications, ensuring transparency regarding the nature and scope of each identified issue.

Vendor: Tips and Tricks HQ

CVE ID Title CVSS Severity Published
CVE-2026-2383 Simple Download Monitor <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field CWE-79 6.4 Medium 2026-02-27
CVE-2025-8977 Simple Download Monitor <= 3.9.33 - Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality CWE-89 6.5 Medium 2025-08-28
CVE-2025-58197 WordPress Simple Download Monitor Plugin <= 3.9.34 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium 2025-08-27
CVE-2025-24663 WordPress Simple Download Monitor plugin <= 3.9.25 - SQL Injection vulnerability CWE-89 7.6 High 2025-01-24
CVE-2021-24692 Simple Download Monitor < 3.9.5 - Contributor+ Arbitrary File Download via Path Traversal CWE-22 6.5 - 2022-03-14
CVE-2021-24696 Simple Download Monitor < 3.9.9 - Multiple CSRF CWE-352 8.8 - 2022-01-24
CVE-2021-24694 Simple Download Monitor < 3.9.11 - Contributor+ Stored Cross-Site Scripting via Shortcodes CWE-79 5.4 - 2022-01-24
CVE-2021-24698 Simple Download Monitor < 3.9.6 - Arbitrary Thumbnails Removal CWE-284 4.3 - 2021-11-08
CVE-2021-24697 Simple Download Monitor < 3.9.5 - Reflected Cross-Site Scripting CWE-79 6.1 - 2021-11-08
CVE-2021-24695 Simple Download Monitor < 3.9.6 - Unauthenticated Log Access CWE-425 5.3 - 2021-11-08
CVE-2021-24693 Simple Download Monitor < 3.9.5 - Contributor+ Stored Cross-Site Scripting via File Thumbnail CWE-79 7.6 - 2021-11-08
CVE-2020-5651 WordPress Simple Download Monitor SQL注入漏洞 8.8 - 2020-10-21
CVE-2020-5650 WordPress Simple Download Monitor 跨站脚本漏洞 6.1 - 2020-10-21

All 13 known CVE vulnerabilities affecting Simple Download Monitor with full Chinese analysis, references, and POCs where available.