Junglewise Threat Intelligence

CVE-2026-87935: WordPress Paid Downloads arbitrary file upload

CVE-2026-87935 · Severity: high · CVSS 8.1 · Published 2026-09-17

Vendors: Wordpress.

Executive brief

The Paid Downloads plugin for WordPress contains a critical vulnerability that allows unauthenticated attackers to upload executable files to a website without proper authorization checks. An attacker can exploit this to upload malicious code that executes on the web server, potentially gaining complete control over the website and its underlying server. This is especially dangerous on servers running nginx or LiteSpeed, where file protections are more easily bypassed.

Technical details

The vulnerability is an arbitrary file upload flaw in the admin_request_handler function of the Paid Downloads WordPress plugin (versions ≤3.15). The function lacks proper authorization and file type validation, yet is accessible to unauthenticated users via /wp-admin/admin-post.php because the WordPress is_admin() check evaluates to true for this endpoint. Attackers can upload files with executable extensions (e.g., .php) without authentication. On Apache servers with AllowOverride enabled, an uploaded .htaccess file can be used to prevent direct HTTP access to uploads; however, on nginx, LiteSpeed, or Apache without AllowOverride, uploaded executables can be directly accessed and executed, leading to remote code execution. Patches should be available from the plugin author; administrators should update immediately.

Affected products

  • WordPress Paid Downloads up to and including 3.15

Timeline

  • 2026-09-17: disclosed

References