PatchSiren

ichurakov CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ichurakov CVE published 2026-09-17

CVE-2026-87935

The Paid Downloads plugin for WordPress has a vulnerability allowing arbitrary file uploads, which can lead to remote code execution. This issue affects all versions up to and including 3.15 and is due to missing authorization and file type validation in the admin_request_handler function. The vulnerability is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php.