In Download Manager plugin for WordPress versions up to and including 3.3.12 a high severity vulnerability (CVE-2025-3404) was detected. This vulnerability allows authenticated attackers with Author-level access or higher to delete arbitrary files on the server via insufficient file path validation in the savePackage function, potentially leading to remote code execution if critical files like wp-config.php are removed. To address this issue, users should update Download Manager plugin to versions 3.3.13 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3404.
WordPress: Authenticated Users Can Delete Arbitrary Files Leading to RCE in Download Manager Plugin
by the Hossted team
21.04.2025