File Upload Vulnerability in wp-downloadmanager Plugin by WordPress
CVE-2026-18933

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 August 2026

What is CVE-2026-18933?

The wp-downloadmanager plugin for WordPress has a vulnerability that permits admin users to upload files without proper validation. This includes lacking checks on file extensions and MIME types, which can lead to unauthorized file uploads. Files uploaded using the download-add.php script can be stored in a web-accessible directory, enabling the possibility of executing arbitrary PHP code due to the absence of any security measures like path sanitization or file type verification. Newer versions of the plugin have addressed these shortcomings, but installations running on version 1.68.11 are particularly exposed to these risks.

Affected Version(s)

wp-downloadmanager 0 < 1.69

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamol_cs
.