Download Counter Button <= 1.8.6.7 - Unauthenticated Arbitrary File Download
Strategic Overview
<= 1.8.6.7CVE-2025-11072Vulnerability Overview
The MelAbu WP Download Counter Button plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 1.8.6.7 via the /download-counter-button/functions/count/download.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Technical Analysis
REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-73 (External Control of File Name or Path) The product allows user input to control or influence paths or file names that are used in filesystem operations.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C