A vulnerability described as critical has been identified in Jeff Starr Simple Download Counter Plugin up to 2.2.2 on WordPress. This vulnerability affects the function simple_download_counter_parse_path. The manipulation results in path traversal.

This vulnerability is reported as CVE-2025-13677. The attack can be launched remotely. No exploit exists.