Arbitrary File Upload Vulnerability in WP-DownloadManager Plugin for WordPress
CVE-2025-10747
7.2HIGH
What is CVE-2025-10747?
The WP-DownloadManager plugin for WordPress suffers from a vulnerability that allows authenticated users with Administrator-level access to upload arbitrary files due to insufficient file type validation within the download-add.php file. This flaw potentially opens the door to remote code execution on the affected server, presenting significant risks to site integrity and security. As the vulnerability affects all versions up to and including 1.68.11, it is crucial for site administrators to apply necessary patches and updates to mitigate these risks.
Affected Version(s)
WP-DownloadManager * <= 1.68.11