Arbitrary File Deletion Vulnerability in WP-DownloadManager Plugin for WordPress
CVE-2025-4799
What is CVE-2025-4799?
The WP-DownloadManager plugin for WordPress has a serious flaw that allows authenticated attackers with administrator-level access to delete arbitrary files from the server. This unrestricted file deletion could enable attackers to remove critical files, such as wp-config.php, which may lead to remote code execution. It is recommended to review and update to the latest version of the plugin to mitigate this security risk. This vulnerability can also be exploited in conjunction with other security issues to further compromise WordPress installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP-DownloadManager * <= 1.68.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved