PT-2025-45082 · WordPress · Wp Download Counter Button

Khaled Alenazi

·

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-11072

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MelAbu WP Download Counter Button WordPress plugin versions through 1.8.6.7
Description The plugin does not properly check the location of files before allowing downloads. This could allow someone without an account to access and download any file on the server. The issue involves a lack of validation of file paths.
Recommendations Update to a version beyond 1.8.6.7.

Exploit

Fix

Related Identifiers

CVE-2025-11072

Affected Products

Wp Download Counter Button