CVE-2025-49995: WordPress Download Attachments plugin <= 1.3.1 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Download Attachments: from n/a through 1.3.1.
Other sources
Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.3.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49995?
CVE-2025-49995 is classified as a high-severity vulnerability due to its potential for unauthorized access through improper access controls.
How do I fix CVE-2025-49995?
To fix CVE-2025-49995, you should update the dFactory Download Attachments plugin to the latest version beyond 1.3.1 that addresses this vulnerability.
What types of systems are affected by CVE-2025-49995?
CVE-2025-49995 affects the dFactory Download Attachments plugin version 1.3.1 and earlier, which is used on WordPress sites.
What can attackers do with CVE-2025-49995?
With CVE-2025-49995, attackers can potentially bypass authorization controls and gain access to restricted files or data.
Is there any mitigation for CVE-2025-49995 until a patch is applied?
While waiting for a patch for CVE-2025-49995, consider restricting user permissions and implementing additional security measures to limit access.