CPE
An unauthenticated arbitrary file upload vulnerability in the Paid Downloads plugin (<= 3.15) allows remote attackers to execute code by bypassing file type validation via the admin_request_handler function.