Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite

2025-03-12 00:00
zhuxuan wu

Strategic Overview

Status
Patched in 3.3.09
Affected PluginDownload Manager
Affected Version<= 3.3.08
CVSS5.4Medium
CVECVE-2025-1785
View all Download Manager vulnerabilities

Vulnerability Overview

The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.

Technical Analysis

REMEDIATION: Update to version 3.3.09, or a newer patched version --- IDENTIFIER: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')) The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C