PT-2025-52542 · WordPress · F70 Lead Document Download

Camilla Flocco

·

Published

2025-12-20

·

Updated

2025-12-20

·

CVE-2025-14633

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions F70 Lead Document Download plugin for WordPress versions through 1.4.4
Description The F70 Lead Document Download plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check within the file download function. An unauthenticated attacker can download any file from the WordPress media library by guessing or enumerating WordPress attachment IDs.
Recommendations Update the F70 Lead Document Download plugin to a version newer than 1.4.4.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14633

Affected Products

F70 Lead Document Download