MelAbu WP Download Counter Button, CVE-2025-11072
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 05, 2025
- Research Description
- The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files.
- Affected versions
-
max 1.8.6.7.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Elizaibots (CVE-2025-49893) , Aug 20, 2025 |