PT-2025-26495 · WordPress · Wp-File-Download

Kevin Camus

·

Published

2025-06-21

·

Updated

2026-04-12

·

CVE-2025-5034

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions wp-file-download versions prior to 6.2.6
Description The wp-file-download WordPress plugin does not properly sanitize and escape a parameter before displaying it on the page, resulting in a Reflected Cross-Site Scripting issue.
Recommendations Update the wp-file-download plugin to version 6.2.6 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-5034

Affected Products

Wp-File-Download