{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/easy-digital-downloads-plugin--3.6.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-12476"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Easy Digital Downloads plugin (\u003c= 3.6.9)"],"_cs_severities":["high"],"_cs_tags":["web","arbitrary-file-upload","rce","wordpress","plugin"],"_cs_type":"advisory","_cs_vendors":["Easy Digital Downloads"],"content_html":"\u003cp\u003eA critical vulnerability, CVE-2026-12476, exists in the Easy Digital Downloads plugin for WordPress, affecting all versions up to and including 3.6.9. This flaw stems from improper file type validation within the \u003ccode\u003eedd_do_ajax_import_file_upload()\u003c/code\u003e function. Instead of robustly checking file contents or relying on WordPress's built-in MIME enforcement (\u003ccode\u003ewp_handle_upload()\u003c/code\u003e), the function only inspects the client-supplied \u003ccode\u003e$_FILES['edd-import-file']['type']\u003c/code\u003e Content-Type header against a narrow allow-list of CSV mime types. Following this superficial check, the \u003ccode\u003emove_uploaded_file()\u003c/code\u003e function is used, allowing files with arbitrary extensions (e.g., \u003ccode\u003e.php\u003c/code\u003e or \u003ccode\u003e.phtml\u003c/code\u003e) to be written to the web-accessible \u003ccode\u003ewp-content/uploads/edd/exports/\u003c/code\u003e directory. This makes it possible for authenticated attackers possessing Shop Manager-level access or higher to upload malicious files, such as web shells, ultimately leading to remote code execution on the compromised server. Defenders should prioritize patching and monitoring for suspicious file uploads and access attempts to the export directory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated attacker with Shop Manager-level or higher privileges accesses the Easy Digital Downloads import file upload functionality, typically found within the WordPress administration interface.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious file, such as a PHP web shell (e.g., \u003ccode\u003eshell.php\u003c/code\u003e), designed to execute arbitrary commands on the server.\u003c/li\u003e\n\u003cli\u003eThe attacker uploads the malicious file via the vulnerable \u003ccode\u003eedd_do_ajax_import_file_upload()\u003c/code\u003e function, manipulating the client-supplied \u003ccode\u003eContent-Type\u003c/code\u003e header to bypass the plugin's insufficient validation logic.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003emove_uploaded_file()\u003c/code\u003e function writes the malicious file with its original, executable extension (e.g., \u003ccode\u003e.php\u003c/code\u003e) to the web-accessible directory: \u003ccode\u003ewp-content/uploads/edd/exports/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an HTTP request to the newly uploaded malicious file, targeting its public URL (e.g., \u003ccode\u003eexample.com/wp-content/uploads/edd/exports/shell.php\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe web server executes the malicious file, granting the attacker remote code execution capabilities on the underlying system, often as the web server's user.\u003c/li\u003e\n\u003cli\u003eThe attacker can then perform further actions such as data exfiltration, creating persistent backdoors, or defacing the website.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-12476 grants attackers remote code execution capabilities on the affected WordPress server. This allows for full compromise of the website, including data theft (e.g., customer information, payment details if stored on the server), website defacement, injection of malicious code into website content, and complete system takeover. Attackers can install persistent backdoors, launch further attacks against other systems, or use the compromised server as a pivot point within the network. The integrity, confidentiality, and availability of the affected WordPress site and potentially other systems on the same host are severely jeopardized.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-12476 by updating the Easy Digital Downloads plugin to version 3.6.10 or later immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect Possible CVE-2026-12476 Post-Exploitation Access\u0026quot; to your SIEM and tune for your environment to identify attempts to access web shells in the Easy Digital Downloads export directory.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for suspicious HTTP POST requests to \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e containing \u003ccode\u003eaction=edd_do_ajax_import_file_upload\u003c/code\u003e, especially if the \u003ccode\u003eContent-Type\u003c/code\u003e header is not a standard CSV type or if it contains suspicious filenames.\u003c/li\u003e\n\u003cli\u003eRegularly review user accounts with Shop Manager-level access or higher, as these are prerequisites for exploiting this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T04:19:05Z","date_published":"2026-07-29T04:19:05Z","id":"https://feed.craftedsignal.io/briefs/2026-07-easy-digital-downloads-file-upload/","summary":"The Easy Digital Downloads plugin for WordPress versions up to and including 3.6.9 is vulnerable to Arbitrary File Upload (CVE-2026-12476) due to insufficient file type validation, allowing authenticated attackers with Shop Manager-level access or higher to upload arbitrary files which can lead to remote code execution.","title":"Easy Digital Downloads Plugin Arbitrary File Upload Leads to RCE (CVE-2026-12476)","url":"https://feed.craftedsignal.io/briefs/2026-07-easy-digital-downloads-file-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - Easy Digital Downloads Plugin (\u003c= 3.6.9)","version":"https://jsonfeed.org/version/1.1"}