Arbitrary File Read Vulnerability in WP-DownloadManager Plugin by WordPress
CVE-2025-4798

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 June 2025

What is CVE-2025-4798?

The WP-DownloadManager plugin prior to version 1.68.10 contains a vulnerability that allows authenticated users with Administrator-level access to read arbitrary files on the server. This occurs due to insufficient restrictions on directory selection during download storage, potentially exposing sensitive configuration and system files, which could lead to further exploitation.

Affected Version(s)

WP-DownloadManager * <= 1.68.10

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jamshed Yergashvoyev
.