CVE-2025-47439: WordPress Download Monitor plugin <= 5.0.22 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor allows PHP Local File Inclusion. This issue affects Download Monitor: from n/a through 5.0.22.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47439?
CVE-2025-47439 has been classified as a critical vulnerability due to its potential for remote file inclusion.
How do I fix CVE-2025-47439?
To fix CVE-2025-47439, upgrade WP Chill Download Monitor to version 5.0.23 or later.
What causes the vulnerability in CVE-2025-47439?
CVE-2025-47439 is caused by improper control of file names for include/require statements in the PHP code.
Which versions of Download Monitor are affected by CVE-2025-47439?
CVE-2025-47439 affects Download Monitor versions from n/a up to and including 5.0.22.
Is CVE-2025-47439 specific to any environment?
CVE-2025-47439 specifically affects the WP Chill Download Monitor environment within WordPress.