{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpresspaid_downloads/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:paid_downloads:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-87935"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Paid Downloads (\u003c= 3.15)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Paid Downloads plugin for WordPress, in all versions up to and including 3.15, contains a critical arbitrary file upload vulnerability. The flaw resides in the admin_request_handler function, which fails to implement necessary authorization checks or file type validation. Because the function is reachable via an unauthenticated request to /wp-admin/admin-post.php, an attacker can upload arbitrary files, including executable scripts, to the web server.\u003c/p\u003e\n\u003cp\u003eThis vulnerability primarily impacts environments where the web server does not honor .htaccess files or where such directives are disabled, including nginx, LiteSpeed, and Apache configurations with 'AllowOverride None'. Successful exploitation grants the attacker the ability to achieve remote code execution on the underlying server. Defenders should focus on monitoring for unauthorized file uploads in the plugin directory and unexpected requests directed at the admin-post.php endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain remote code execution capabilities on the host server. This impact is significant for any WordPress installation utilizing the Paid Downloads plugin, as it could lead to full site compromise, exfiltration of sensitive database content, and further lateral movement within the network. The scope includes any server running the vulnerable versions of the plugin on web server software that does not restrict file execution via .htaccess.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating the Paid Downloads plugin to the latest secure version immediately. If an update is not available, temporarily disable the plugin until a patch is applied.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web access logs for anomalous POST requests to /wp-admin/admin-post.php.\u003c/li\u003e\n\u003cli\u003eAudit the file system for recently uploaded executable files (e.g., .php files) within the plugin upload directories.\u003c/li\u003e\n\u003cli\u003eImplement strict file-type and size limitations on web server configurations.\u003c/li\u003e\n\u003cli\u003eUtilize the Sigma rule provided below to detect potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T05:55:08Z","date_published":"2026-09-17T05:55:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87935-wp-plugin/","summary":"An unauthenticated arbitrary file upload vulnerability in the Paid Downloads plugin (\u003c= 3.15) allows remote attackers to execute code by bypassing file type validation via the admin_request_handler function.","title":"Arbitrary File Upload Vulnerability in Paid Downloads WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87935-wp-plugin/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:paid_downloads:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}