Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter allows Stored XSS. This issue affects Simple Download Counter: from n/a through 2.2.
References
Configurations
History
29 Apr 2025, 18:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Plugin-planet
Plugin-planet simple Download Counter |
|
CPE | cpe:2.3:a:plugin-planet:simple_download_counter:*:*:*:*:*:wordpress:*:* | |
References | () https://patchstack.com/database/wordpress/plugin/simple-download-counter/vulnerability/wordpress-simple-download-counter-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve - Third Party Advisory |
23 Apr 2025, 14:08
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Apr 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-22 10:15
Updated : 2025-04-29 18:52
NVD link : CVE-2025-46240
Mitre link : CVE-2025-46240
CVE.ORG link : CVE-2025-46240
JSON object : View
Products Affected
plugin-planet
- simple_download_counter
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')