- Description
- The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including any local file on the server, such as wp-config.php or /etc/passwd.
- Source
- security@wordfence.com
- NVD status
- Received
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- security@wordfence.com
- CWE-73
- Hype score
- Not currently trending
๐จ CVE-2025-1730 ๐ MEDIUM (6.5) ๐ข specialk - Simple Download Counter ๐๏ธ * ๐ https://t.co/XKwduOWLZw ๐ https://t.co/ViRKzxQQSy ๐ https://t.co/3JsunlBAaa ๐ https://t.co/XfUt5lRF49 #CyberCron #VulnAlert #InfoSec https://t.co/baGPSf2chV
@cybercronai
2 Mar 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1730 The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_downloaโฆ https://t.co/6EyDRC3Efc
@CVEnew
1 Mar 2025
101 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New post from https://t.co/uXvPWJy6tj (CVE-2025-1730 | specialk Simple Download Counter Plugin up to 2.0 on WordPress wp-config.php simple_download_counter_download_handler file inclusion) has been published on https://t.co/SapTJD70EC
@WolfgangSesin
1 Mar 2025
16 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes