CVE-2025-6586: Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload
The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwappluginlocInstall function in all versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6586?
The severity of CVE-2025-6586 is rated as high due to the potential for arbitrary file uploads by authenticated attackers.
How do I fix CVE-2025-6586?
To fix CVE-2025-6586, update the WordPress Download Plugin to version 2.2.9 or later, which addresses the vulnerability.
Who is affected by CVE-2025-6586?
All users of the WordPress Download Plugin versions up to and including 2.2.8 are affected by CVE-2025-6586.
What kind of attacks can CVE-2025-6586 enable?
CVE-2025-6586 can enable attackers to upload arbitrary files, potentially leading to remote code execution on the server.
Is CVE-2025-6586 patched in future releases?
Yes, CVE-2025-6586 has been patched in version 2.2.9 of the WordPress Download Plugin and later versions.