Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9118 | The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server |
Thu, 12 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lana
Lana lana Downloads Manager |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:lana:lana_downloads_manager:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Lana
Lana lana Downloads Manager |
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server | |
| Title | Lana Downloads Manager < 1.10.0 - Admin+ Arbitrary File Download via Path Traversal | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-01T14:58:56.415Z
Reserved: 2025-03-06T14:33:00.667Z
Link: CVE-2025-2048
Updated: 2025-04-01T14:58:45.483Z
Status : Analyzed
Published: 2025-04-01T06:15:48.350
Modified: 2025-06-12T16:57:25.657
Link: CVE-2025-2048
No data.
OpenCVE Enrichment
No data.
EUVD