Arbitrary File Deletion Vulnerability in WP-DownloadManager Plugin for WordPress
CVE-2025-4799

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 June 2025

What is CVE-2025-4799?

The WP-DownloadManager plugin for WordPress has a serious flaw that allows authenticated attackers with administrator-level access to delete arbitrary files from the server. This unrestricted file deletion could enable attackers to remove critical files, such as wp-config.php, which may lead to remote code execution. It is recommended to review and update to the latest version of the plugin to mitigate this security risk. This vulnerability can also be exploited in conjunction with other security issues to further compromise WordPress installations.

Affected Version(s)

WP-DownloadManager * <= 1.68.10

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jamshed Yergashvoyev
.
CVE-2025-4799 : Arbitrary File Deletion Vulnerability in WP-DownloadManager Plugin for WordPress