Arbitrary File Upload Vulnerability in Easy Digital Downloads Plugin for WordPress
CVE-2026-12476
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-12476?
The Easy Digital Downloads plugin is susceptible to an arbitrary file upload vulnerability due to inadequate validation of file types in its import functionality. Specifically, the edd_do_ajax_import_file_upload() function allows the client-supplied MIME type to bypass core validations, enabling attackers with Shop Manager-level access or higher to upload potentially harmful files directly to the web-accessible directory. This flaw poses a significant threat as it could facilitate remote code execution, compromising the integrity and security of the affected site.
Affected Version(s)
Easy Digital Downloads β eCommerce Payments and Subscriptions made easy 0 <= 3.6.9