Логотип exploitDog
bind:CVE-2025-2519
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-2519

Количество 2

Количество 2

nvd логотип

CVE-2025-2519

10 месяцев назад

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_download_file' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x3hf-px6r-w9gq

10 месяцев назад

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_download_file' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary files.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-2519

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_download_file' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary files.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-x3hf-px6r-w9gq

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_download_file' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download arbitrary files.

CVSS3: 6.5
0%
Низкий
10 месяцев назад

Уязвимостей на страницу