CVE-2025-3056: Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3056?
CVE-2025-3056 is considered a high severity vulnerability due to the potential impact of stored cross-site scripting.
How do I fix CVE-2025-3056?
To fix CVE-2025-3056, update the WordPress Download Manager plugin to version 3.3.13 or higher, which includes the necessary security patches.
Who is affected by CVE-2025-3056?
CVE-2025-3056 affects all versions of the WordPress Download Manager plugin up to and including version 3.3.12.
What types of attacks can CVE-2025-3056 enable?
CVE-2025-3056 can allow authenticated attackers to execute malicious scripts via SVG file uploads, potentially compromising user data.
Is there a workaround for CVE-2025-3056?
There is no known effective workaround for CVE-2025-3056, and updating to the latest version is the recommended solution.