Simple Download Counter <= 2.0 - Authenticated (Author+) Arbitrary File Read

2025-02-28 00:00
omstaendlig

Strategic Overview

Status
Patched in 2.1
Affected Version<= 2.0
CVSS6.5Medium
CVECVE-2025-1730
View all Simple Download Counter vulnerabilities

Vulnerability Overview

The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including any local file on the server, such as wp-config.php or /etc/passwd.

Technical Analysis

REMEDIATION: Update to version 2.1, or a newer patched version --- IDENTIFIER: CWE-73 (External Control of File Name or Path) The product allows user input to control or influence paths or file names that are used in filesystem operations.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C