๐Ÿ” CVE Alert

CVE-2025-11072

MEDIUM 5.3

Download Counter Button <= 1.8.6.7 - Unauthenticated Arbitrary File Download

CVSS Score
5.3
EPSS Score
0.1%
EPSS Percentile
28th

The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files.

Vendor unknown
Product melabu wp download counter button
Published Nov 5, 2025
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown melabu wp download counter button

Be the first to know when new medium vulnerabilities affecting unknown melabu wp download counter button are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / MelAbu WP Download Counter Button
0 โ‰ค 1.8.6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/538117c5-b04c-45fc-a953-6f619fdf7eaf/

Credits

Khaled Alenazi (Nxploited) WPScan