CVE-2021-24697: Tipsandtricks-Hq Simple Download Monitor

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

Affected products

Published 2021-11-08. Last modified 2026-06-17.