5.4
CVSSv3

CVE-2025-1785

CVSSv4: NA | CVSSv3: 5.4 | CVSSv2: NA | VMScore: 640 | EPSS: 0.00563 | KEV: Not Included
Published: 13/03/2025 Updated: 13/03/2025

Vulnerability Summary

Directory Traversal in WordPress Download Manager Plugin Before 3.3.08

The Download Manager plugin for WordPress contains a serious vulnerability in versions up to and including 3.3.08. Through the 'wpdm_newfile' action, an authenticated attacker with Author-level access or higher permissions can perform a directory traversal attack. This means the attacker can potentially overwrite specific file types in locations outside the intended directory, which could result in a system disruption or denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

codename065 download manager