HIGH
ichurakov
CVE published 2026-09-17
CVE-2026-87935
The Paid Downloads plugin for WordPress has a vulnerability allowing arbitrary file uploads, which can lead to remote code execution. This issue affects all versions up to and including 3.15 and is due to missing authorization and file type validation in the admin_request_handler function. The vulnerability is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php.