Description
WordPress Plugin Download Plugin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently activate plugins that are already installed. WordPress Plugin Download Plugin version 1.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:4ED8296E-1306-481F-9A22-723B051122C0
https://plugins.svn.wordpress.org/download-plugin/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WordPress Landing Pages Unspecified Vulnerability (1.8.1)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2017-5340)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-11585)
Oracle Database Server CVE-2009-1969 Vulnerability (CVE-2009-1969)
MySQL Uncontrolled Resource Consumption Vulnerability (CVE-2025-50097)