CVE-2025-1785
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Mar 13, 2025
CWE ID 22
Summary
CVE-2025-1785 is a directory traversal vulnerability affecting the Download Manager plugin for WordPress. This issue, present in versions up to 3.3.08, allows authenticated attackers with Author-level access or higher to overwrite select file types outside of the intended directory. The exploitation of this vulnerability can result in a denial of service.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.