Description
The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9118 | The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server |
References
History
Thu, 12 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lana
Lana lana Downloads Manager |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:lana:lana_downloads_manager:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Lana
Lana lana Downloads Manager |
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server | |
| Title | Lana Downloads Manager < 1.10.0 - Admin+ Arbitrary File Download via Path Traversal | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-01T14:58:56.415Z
Reserved: 2025-03-06T14:33:00.667Z
Link: CVE-2025-2048
Updated: 2025-04-01T14:58:45.483Z
Status : Analyzed
Published: 2025-04-01T06:15:48.350
Modified: 2025-06-12T16:57:25.657
Link: CVE-2025-2048
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD