File Upload Vulnerability in wp-downloadmanager Plugin by WordPress
CVE-2026-18933
7.2HIGH
What is CVE-2026-18933?
The wp-downloadmanager plugin for WordPress has a vulnerability that permits admin users to upload files without proper validation. This includes lacking checks on file extensions and MIME types, which can lead to unauthorized file uploads. Files uploaded using the download-add.php script can be stored in a web-accessible directory, enabling the possibility of executing arbitrary PHP code due to the absence of any security measures like path sanitization or file type verification. Newer versions of the plugin have addressed these shortcomings, but installations running on version 1.68.11 are particularly exposed to these risks.
Affected Version(s)
wp-downloadmanager 0 < 1.69