Логотип exploitDog
bind:CVE-2025-14633
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-14633

Количество 2

Количество 2

nvd логотип

CVE-2025-14633

около 2 месяцев назад

The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to download any file from the WordPress media library by guessing or enumerating WordPress attachment IDs.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-j286-265p-82mw

около 2 месяцев назад

The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to download any file from the WordPress media library by guessing or enumerating WordPress attachment IDs.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-14633

The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to download any file from the WordPress media library by guessing or enumerating WordPress attachment IDs.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-j286-265p-82mw

The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to download any file from the WordPress media library by guessing or enumerating WordPress attachment IDs.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу