Cross-Site Scripting
8 records47.1%First: 2018. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 17 vulnerability records associated with Simple Download Monitor, published between 2016 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2016 | 1 | |
| 2018 | 2 | |
| 2020 | 2 | |
| 2021 | 8 | |
| 2025 | 3 | |
| 2026 | 1 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 11.8% |
| High | 2 | 11.8% |
| Medium | 13 | 76.5% |
First: 2018. Latest: 2026.
First: 2020. Latest: 2025.
First: 2016. Latest: 2021.
First: 2021. Latest: 2021.
First: 2021. Latest: 2021.
First: 2021. Latest: 2021.
First: 2021. Latest: 2021.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.0.63.9.353.9.343.9.263.9.113.9.93.9.63.9.53.8.93.3.93.5.43.2.9Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.0.5 | Simple Download Monitor <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field | February 26, 2026 | 4.0.6 | Medium |
*-3.9.34 | Simple Download Monitor <= 3.9.34 - Authenticated (Contributor+) Stored Cross-Site Scripting | August 27, 2025 | 3.9.35 | Medium |
*-3.9.33 | Simple Download Monitor <= 3.9.33 - Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality | August 27, 2025 | 3.9.34 | Medium |
*-3.9.25 | Simple Download Monitor <= 3.9.25 - Authenticated (Administrator+) SQL Injection | January 24, 2025 | 3.9.26 | Medium |
*-3.9.10 | Simple Download Monitor <= 3.9.10 - Contributor+ Stored Cross-Site Scripting via Shortcodes | December 21, 2021 | 3.9.11 | Medium |
*-3.9.8 | Simple Download Monitor <= 3.9.8 - Multiple Cross-Site Request Forgery vulnerabilities | December 21, 2021 | 3.9.9 | High |
[*, 3.9.5) | Simple Download Monitor <= 3.9.4 - Reflected Cross-Site Scripting | October 5, 2021 | 3.9.5 | Medium |
*-3.9.5 | Simple Download Monitor <= 3.9.5 - Log Reset | October 5, 2021 | 3.9.6 | Medium |
[*, 3.9.6) | Simple Download Monitor <= 3.9.5 - Sensitive Data Exposure | October 5, 2021 | 3.9.6 | Medium |
[*, 3.9.6) | Simple Download Monitor <= 3.9.5 - Contributor+ Arbitrary Thumbnail Removal | October 5, 2021 | 3.9.6 | Medium |
*-3.9.4 | Simple Download Monitor <= 3.9.4 - Contributor+ Stored Cross-Site Scripting via File Thumbnail | October 5, 2021 | 3.9.5 | Critical |
[*, 3.9.5) | Simple Download Monitor <= 3.9.4 - Contributor+ Arbitrary File Download | September 2, 2021 | 3.9.5 | Medium |
*-3.8.8 | Simple Download Monitor <= 3.8.8 - SQL Injection | October 21, 2020 | 3.8.9 | High |
*-3.3.8 | Simple Download Monitor <= 3.8.8 - Unauthenticated Stored Cross-Site Scripting | October 21, 2020 | 3.3.9 | Medium |
[*, 3.5.4) | Simple Download Monitor < 3.5.4 - Authenticated Stored Cross-Site Scripting | January 2, 2018 | 3.5.4 | Medium |
[*, 3.5.4) | Simple Download Monitor < 3.5.4 - Authenticated Stored Cross-Site Scripting | January 2, 2018 | 3.5.4 | Medium |
*-3.2.8 | Simple Download Monitor <= 3.2.8 - Missing Authorization | January 19, 2016 | 3.2.9 | Critical |
Selected source records
Published: February 26, 2026
Published: August 27, 2025
Published: August 27, 2025
Published: January 24, 2025
Published: December 21, 2021
Published: December 21, 2021
Published: October 5, 2021
Published: October 5, 2021
Published: January 19, 2016
Published: October 5, 2021
Published: December 21, 2021
Published: October 21, 2020
Published: August 27, 2025
Published: September 2, 2021
Published: January 2, 2018
Published: February 26, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.