PT-2025-5480 · WordPress · Wordpress Download Manager Premium Packages

Webula

·

Published

2024-12-18

·

Updated

2025-01-24

·

CVE-2025-24659

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions WordPress Download Manager Premium Packages versions n/a through 5.9.6
Description The issue is related to an SQL Injection vulnerability, specifically an Improper Neutralization of Special Elements used in an SQL Command. This allows for Blind SQL Injection, which can be exploited.
Recommendations For WordPress Download Manager Premium Packages versions n/a through 5.9.6, update to a version later than 5.9.6 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-03231
CVE-2025-24659

Affected Products

Wordpress Download Manager Premium Packages