Junglewise Threat Intelligence

CVE-2021-47940: WordPress Download From Files arbitrary file upload in AJAX handler

CVE-2021-47940 · Severity: critical · CVSS 9.8 · Published 2026-05-10

Executive brief

The Download From Files plugin for WordPress, which allows users to manage and serve documents from a website's filesystem, contains a critical security flaw. An unauthenticated attacker can upload malicious files, such as web shells, directly to the server. This could lead to a complete takeover of the website, theft of sensitive data, or the installation of ransomware.

Technical details

An arbitrary file upload vulnerability exists in the 'Download From Files' WordPress plugin due to missing authentication and insufficient validation in its AJAX file upload handler. Attackers can send unauthenticated POST requests to the 'admin-ajax.php' endpoint using the 'download_from_files_617_fileupload' action. By manipulating the 'allowExt' parameter, an attacker can bypass intended file extension restrictions and upload executable PHP files (e.g., .php4 or .phtml) directly to the web root. This allows for remote code execution (RCE) on the underlying server. The plugin has been permanently closed on the WordPress repository due to this issue.

Affected products

  • WordPress Plugin Download From Files <= 1.48

Timeline

  • 2021-09-10: disclosed: Initial exploit discovery by researcher spacehen
  • 2021-09-13: other: Exploit published on Exploit-DB
  • 2021-09-15: other: Plugin permanently closed on WordPress.org repository
  • 2026-05-10: advisory: CVE published/updated via VulnCheck/NVD

References