The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/05c664e8-110e-4a31-8377-41a0422508a7/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-04-01 06:15
Updated : 2025-06-12 16:57
NVD link : CVE-2025-2048
Mitre link : CVE-2025-2048
CVE.ORG link : CVE-2025-2048
JSON object : View
Products Affected
lana
- lana_downloads_manager
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
