CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Mar 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector. |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Jan 24, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerabilit...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Jan 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcod...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, lead...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the log...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cro...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Oct 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL. |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Oct 21, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. |