Impact
The vulnerability in the WordPress plugin allows an attacker who holds a subscriber-level account or higher to delete files, empty the trash, move files between categories, or toggle file publication status. Because the plugin accepts a 'task' parameter without verifying that the current user has the required rights, the only required condition is that the user is authenticated. The result is loss of user data, potential removal of critical content, and exposure to data integrity compromise.
Affected Systems
The issue affects the WordPress plugin "WP File Download" from JoomUnited, versions 6.3.9 and earlier. Sites running any of those releases, regardless of other WordPress configuration, are affected. Only users with the plugin installed are impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, classifying it as high severity. The EPSS score is not available, so the exploitation frequency cannot be quantified, but the lack of an authority check makes the attack trivial for any authenticated user. The vulnerability is not present in the CISA KEV catalog, but it remains a critical concern for sites using the plugin, as an attacker can gain persistence by creating or modifying files. The attack vector is internal; an attacker must already have an account on the WordPress site with subscriber-level or higher privileges. Exploitation requires sending a request to the plugin's endpoints with a crafted 'task' parameter and the target file identifier.
OpenCVE Enrichment