← WordPress Vulnerabilities
WordPress security by component

Simple Download Counter

Simple Download Counter is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Mar 26, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: simple-download-counter

CVE-2026-4278: Simple Download Counter: Cross-site scripting

Simple Download Counter is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.3.

PublishedMar 26, 2026
Known safe version> 2.3
Safe version
Mar 26, 2026 CVE-2026-4278
Simple Download Counter: Cross-site scripting
Simple Download Counter is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.3.
> 2.3
CVE6.4
NVDPending
Dec 10, 2025 CVE-2025-13677
Simple Download Counter: Filesystem traversal
Simple Download Counter is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Apr 22, 2025 CVE-2025-46240
Simple Download Counter: Cross-site scripting
Simple Download Counter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 01, 2025 CVE-2025-1730
Simple Download Counter: Filesystem traversal
Simple Download Counter is affected by filesystem traversal. Exploitation requires at least author-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending
Sep 09, 2023 CVE-2023-4838
Simple Download Counter: Cross-site scripting
Simple Download Counter is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4