CVE-2025-11072
Download Counter Button <= 1.8.6.7 - Unauthenticated Arbitrary File Download
CVSS Score
5.3
EPSS Score
0.1%
EPSS Percentile
28th
The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files.
| Vendor | unknown |
| Product | melabu wp download counter button |
| Published | Nov 5, 2025 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown melabu wp download counter button
Be the first to know when new medium vulnerabilities affecting unknown melabu wp download counter button are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / MelAbu WP Download Counter Button
0 โค 1.8.6.7
References
Credits
Khaled Alenazi (Nxploited) WPScan