CVE-2025-49995 Information

Description

Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Download Attachments: from n/a through 1.3.1.

Reference

https://patchstack.com/database/wordpress/plugin/download-attachments/vulnerability/wordpress-download-attachments-plugin-1-3-1-insecure-direct-object-references-idor-vulnerability?_s_id=cve

CNNVD-202506-2711 (Published: 2025-06-20)

Share on: