CVE-2025-2048: Lana Downloads Manager
Medium severity, CVSS 4.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server
Affected products
- Lana Lana Downloads Manager: before 1.10.0 (fixed in 1.10.0)
Published 2025-04-01. Last modified 2026-06-17.