Arbitrary File Upload Vulnerability in Paid Downloads Plugin for WordPress
CVE-2026-87935

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2026

What is CVE-2026-87935?

The Paid Downloads plugin for WordPress is susceptible to an arbitrary file upload vulnerability. This issue arises from inadequate authorization and file type validation in the admin_request_handler function, allowing unauthenticated attackers to upload potentially malicious files through the /wp-admin/admin-post.php endpoint. If executed in environments like Apache where AllowOverride is enabled, uploaded files might be excluded from direct access due to .htaccess restrictions. However, exploitability remains for setups that do not uphold .htaccess rules, such as nginx or LiteSpeed servers.

Affected Version(s)

Paid Downloads 0 <= 3.15

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Spy0x7
.