Impact
The flaw is a classic cross‑site scripting vulnerability in WP File Download versions 6.3.6 and earlier, where user‑controlled input is rendered without proper neutralization. Because the plugin does not require any authentication to process the vulnerable parameter, any audience that can view the affected page is exposed. An injected script could steal session cookies, modify page content, or redirect the user to a malicious site, thereby compromising confidentiality, integrity, and availability of the web application.
Affected Systems
WordPress sites that have installed the WP File Download plugin from Joomunited and are running a bundled release of 6.3.6 or older. The vulnerability affects every site visitor, regardless of whether the user is logged in, as the exploit is triggered via publicly accessible plugin URLs.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as High severity. No EPSS score is provided, so the exploitation probability cannot be quantified at this time, but the lack of authentication requirements removes a common access barrier. The flaw is not listed in the CISA KEV catalog, indicating no known public exploitation yet. Based on the description, it is that an attacker can trigger the flaw by crafting a malicious URL that includes the vulnerable query parameter or by injecting malicious JavaScript into any form field processed by the plugin, making the attack possible from remote users without special privileges.
OpenCVE Enrichment