PT-2025-39512 · WordPress · Wp-Downloadmanager

Sunnatillo Abdivasiyev

·

Published

2025-09-26

·

Updated

2025-10-01

·

CVE-2025-10747

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP-DownloadManager plugin for WordPress versions prior to 1.68.12
Description The WP-DownloadManager plugin for WordPress is susceptible to unrestricted file uploads because of a lack of file type validation within the download-add.php file. This allows attackers with Administrator-level access or higher to upload arbitrary files to the server, potentially leading to remote code execution.
Recommendations Update the WP-DownloadManager plugin to version 1.68.12 or later.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10747

Affected Products

Wp-Downloadmanager