Arbitrary File Deletion in Easy Digital Downloads by Pippins Plugins
CVE-2026-66476

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

What is CVE-2026-66476?

The Easy Digital Downloads plugin for WordPress, specifically versions up to and including 3.6.9, contains a vulnerability that allows administrators to arbitrarily delete files from the server. This issue arises from the way the plugin handles file deletion requests, potentially leading to unauthorized removal of critical files. Website owners utilizing this plugin should take immediate steps to secure their installations and consider upgrading to a patched version.

Affected Version(s)

Easy Digital Downloads <= 3.6.9

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.