VYPR

wp-file-download

by WordPress

CVEs (3)

  • CVE-2026-14982HigSep 2, 2026
    risk 0.53cvss 8.1epss 0.01

    The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary…

  • CVE-2025-5034HigJun 21, 2025
    risk 0.46cvss 7.1epss 0.00

    The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

  • CVE-2026-14975MedSep 5, 2026
    risk 0.42cvss 6.5epss 0.01

    The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary…