Descripción
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the -sdc_menu- shortcode in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the -text- and -cat- attributes. The -text- attribute is output directly into HTML content on line 159 without any escaping (e.g., esc_html()). The -cat- attribute is used unescaped in HTML class attributes on lines 135 and 157 without esc_attr(). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS 6.4EPSS 0.23900000000000002%Riesgo 0.65
Ver fuente- Publicación
- 2026-03-26 05:16:39
- Versiones afectadas
- <=2.3
- Tipo
- Installed app
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N