Impact
The WP File Download plugin contains insufficient file path validation in its delete function, enabling authenticated attackers with subscriber-level access to delete arbitrary files on the server. By targeting sensitive files such as wp-config.php, an attacker can execute remote code, creating a severe compromise risk.
Affected Systems
All versions of the JoomUnited WP File Download plugin for WordPress are affected. The vulnerability is present in every release up to 6.3.4 and likely earlier versions.
Risk and Exploitability
The vulnerability scores a CVSS score of 8.1, indicating a high severity impact. Although the EPSS score is not available, the lack of authentication and capability checks, combined with the two‑stage exploit requirement, suggests a realistic exploitation risk for attackers with subscriber access. The vulnerability is not listed in CISA’s KEV catalog, but administrators should still prioritize remediation due to the potential for remote code execution.
OpenCVE Enrichment