CVE-2025-5034: WP File Download < 6.2.6 - Reflected XSS
Published Jun 21, 2025
·Updated
The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Affected Software
2 affected components
WP Media WP File Download<6.2.6
JoomUnited Wp File Download Wordpress<6.2.6
Event History
Jun 21, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5034?
CVE-2025-5034 has been classified as a medium severity vulnerability due to the potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2025-5034?
To fix CVE-2025-5034, update the WP File Download plugin to version 6.2.6 or later.
3
What type of vulnerability is CVE-2025-5034?
CVE-2025-5034 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the WP File Download plugin.
4
Who is affected by CVE-2025-5034?
Websites using WP Media WP File Download plugin versions prior to 6.2.6 are affected by CVE-2025-5034.
5
What causes CVE-2025-5034?
CVE-2025-5034 is caused by the plugin's failure to properly sanitize and escape parameters before outputting them on the page.