Simple Download Counter Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A path traversal vulnerability has been identified in the Simple Download Counter plugin for WordPress, affecting all versions through 2.2.2. This vulnerability arises from inadequate path validation in the 'simple_download_counter_parse_path()' function, allowing authenticated attackers with Administrator-level access to read arbitrary files on the server. Sensitive files such as database credentials in 'wp-config.php' or other system files could be exposed. Although the plugin's author has released a patch in version 2.2.3, the vulnerability remains in earlier versions, including 2.2.2.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server, including database credentials and other critical system files.

Remediation

Users are advised to update the Simple Download Counter plugin to version 2.2.3 or later.

Added: Dec 10, 2025, 4:18 AM
Updated: Dec 10, 2025, 4:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.5
remediation
7.7
relevance
1.4
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.