
Cloud Vulnerability DB
A community-led vulnerabilities database
Cross-site scripting vulnerability (CVE-2020-5650) affects Simple Download Monitor plugin version 3.8.8 and earlier for WordPress. The vulnerability was discovered and disclosed on October 21, 2020, allowing remote attackers to inject arbitrary scripts via unspecified vectors. The affected software is a WordPress plugin developed by Tips and Tricks HQ that helps manage and track digital file downloads (JVN Advisory, NVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). It received a CVSS v3.1 Base Score of 6.1 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The attack vector is network-based, requires low attack complexity, needs no privileges, but does require user interaction. The scope is changed, with low impact on both confidentiality and integrity, and no impact on availability (NVD).
When exploited, this vulnerability allows attackers to execute arbitrary scripts on the logged-in user's web browser. This could potentially lead to theft of sensitive information, session hijacking, or other malicious actions within the context of the affected WordPress site (JVN Advisory).
The vulnerability requires no authentication to exploit but does need user interaction. The attack vector is network-accessible, making it possible to exploit remotely. The attack complexity is rated as low, indicating that the vulnerability is relatively straightforward to exploit (NVD).
Users are advised to update the Simple Download Monitor plugin to a version newer than 3.8.8. The update can be performed through the WordPress plugin management interface according to the information provided by the developer (JVN Advisory, WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."