PT-2025-50302 · WordPress · Wordpress Simple Download Counter
Camilla Flocco
·
Published
2025-12-10
·
Updated
2025-12-10
·
CVE-2025-13677
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress Simple Download Counter plugin versions up to and including 2.2.2
Description
The Simple Download Counter plugin for WordPress has a path traversal issue. Insufficient path validation in the
simple download counter parse path() function allows authenticated attackers with Administrator-level access or higher to read arbitrary files on the server. These files may contain sensitive information, such as database credentials (wp-config.php) or system files. The vendor has disabled remote file downloads from arbitrary locations on multi-sites and provided a warning to site owners in the readme.txt file upon installation.Recommendations
Update to a version beyond 2.2.2.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Simple Download Counter