Arbitrary File Read Vulnerability in WP-DownloadManager Plugin by WordPress
CVE-2025-4798
4.9MEDIUM
What is CVE-2025-4798?
The WP-DownloadManager plugin prior to version 1.68.10 contains a vulnerability that allows authenticated users with Administrator-level access to read arbitrary files on the server. This occurs due to insufficient restrictions on directory selection during download storage, potentially exposing sensitive configuration and system files, which could lead to further exploitation.
Affected Version(s)
WP-DownloadManager * <= 1.68.10