Description
The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_neofix_sdl_edit' AJAX endpoint along with many others in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to alter many of the plugin's settings/downloads and inject malicious web scripts.
Published: 2025-11-08
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification and stored XSS via AJAX endpoint
Action: Apply Patch
AI Analysis

Impact

The Simple Downloads List plugin for WordPress lacks a capability check on the wp_ajax_neofix_sdl_edit AJAX endpoint and several others, enabling authenticated users with Subscriber level or higher to alter plugin settings and downloads. By sending crafted requests, an attacker can inject malicious scripts that are stored and executed on the site, potentially leading to defacement, data tampering, or further compromise. This flaw is classified as missing authorization (CWE‑862).

Affected Systems

Simple Downloads List plugin for WordPress, versions up to and including 1.4.3. Affected users are those logged in with Subscriber or higher roles; plugin administrators and higher privileged accounts are also able to exploit the endpoint. The vulnerability resides in the plugin’s backend admin panel and its AJAX handling code.

Risk and Exploitability

The CVSS score of 6.4 denotes moderate severity. The EPSS score of less than 1% indicates a very low probability of being exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires the attacker to be authenticated and to have at least Subscriber access, then to invoke the vulnerable AJAX endpoint from a browser or HTTP client. Successful exploitation permits unauthorized configuration changes and stored cross‑site scripting on the site. The combination of moderate impact and low exploitation likelihood suggests close monitoring but prioritizes remediation if the site’s audience includes vulnerable users.

Generated by OpenCVE AI on April 21, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Simple Downloads List plugin to version 1.5.0 or later, which adds the missing capability checks and XSS safeguards.
  • Disable or remove the Simple Downloads List plugin if an upgrade cannot be performed immediately to eliminate the attack surface.
  • Trim Subscriber or higher role permissions so that those users cannot access the wp_ajax_neofix_sdl_edit endpoint, for example by using a role‑management plug‑in to restrict Ajax capabilities.

Generated by OpenCVE AI on April 21, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Neofix
Neofix simple Downloads List
Wordpress
Wordpress wordpress
Vendors & Products Neofix
Neofix simple Downloads List
Wordpress
Wordpress wordpress

Sat, 08 Nov 2025 02:45:00 +0000

Type Values Removed Values Added
Description The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_neofix_sdl_edit' AJAX endpoint along with many others in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to alter many of the plugin's settings/downloads and inject malicious web scripts.
Title Simple Downloads List <= 1.4.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Neofix Simple Downloads List
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:23:39.130Z

Reserved: 2025-10-31T21:49:34.280Z

Link: CVE-2025-12583

cve-icon Vulnrichment

Updated: 2025-11-10T20:17:32.061Z

cve-icon NVD

Status : Deferred

Published: 2025-11-08T03:15:36.350

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-12583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T02:00:12Z

Weaknesses