Description
The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_neofix_sdl_edit' AJAX endpoint along with many others in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to alter many of the plugin's settings/downloads and inject malicious web scripts.
Problem types
Product status
* (semver)
Timeline
| 2025-11-01: | Vendor Notified |
| 2025-11-07: | Disclosed |
Credits
Md. Moniruzzaman Prodhan
References
www.wordfence.com/...-383b-48f5-be63-61cd692a18a0?source=cve
plugins.trac.wordpress.org/.../adminpanel_v3.php?rev=3388438
plugins.trac.wordpress.org/...gs/1.5.0&sfp_email=&sfph_mail=