CVE-2025-1785

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 13, 2025
CWE ID 22

Summary

CVE-2025-1785 is a directory traversal vulnerability affecting the Download Manager plugin for WordPress. This issue, present in versions up to 3.3.08, allows authenticated attackers with Author-level access or higher to overwrite select file types outside of the intended directory. The exploitation of this vulnerability can result in a denial of service.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share