CVE-2025-2048: Lana Downloads Manager

Medium severity, CVSS 4.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server

Affected products

  • Lana Lana Downloads Manager: before 1.10.0 (fixed in 1.10.0)

Published 2025-04-01. Last modified 2026-06-17.