Arbitrary File Upload Vulnerability in Paid Downloads Plugin for WordPress
CVE-2026-87935
8.1HIGH
What is CVE-2026-87935?
The Paid Downloads plugin for WordPress is susceptible to an arbitrary file upload vulnerability. This issue arises from inadequate authorization and file type validation in the admin_request_handler function, allowing unauthenticated attackers to upload potentially malicious files through the /wp-admin/admin-post.php endpoint. If executed in environments like Apache where AllowOverride is enabled, uploaded files might be excluded from direct access due to .htaccess restrictions. However, exploitability remains for setups that do not uphold .htaccess rules, such as nginx or LiteSpeed servers.
Affected Version(s)
Paid Downloads 0 <= 3.15