{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-file-download-all-versions/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:wp_file_download:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-14982"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP File Download (all versions)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient input validation in its file management functions. An authenticated attacker with subscriber-level access can exploit this flaw to delete files outside the intended directories, including critical WordPress configuration files such as wp-config.php. The vulnerability persists across all plugin versions, highlighting a lack of capability checks and nonce enforcement in the 'file.save' and 'file.delete' AJAX endpoints. Successful exploitation could allow an attacker to delete the wp-config.php file, triggering a re-installation process that may lead to site compromise or complete remote code execution. Defenders should prioritize auditing web server access logs for anomalous POST requests directed at these specific plugin endpoints.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates as a user with at least subscriber-level privileges on the WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the plugin's 'file.save' endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a path traversal payload within the file metadata or path parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin application fails to sanitize the input, persisting the malicious path string into the plugin's internal database/metadata store.\u003c/li\u003e\n\u003cli\u003eAttacker sends a second HTTP POST request targeting the 'file.delete' endpoint.\u003c/li\u003e\n\u003cli\u003eThe application retrieves the malicious metadata and passes the path-traversed string to an unvalidated 'unlink' system call.\u003c/li\u003e\n\u003cli\u003eThe system deletes the specified sensitive file, such as 'wp-config.php'.\u003c/li\u003e\n\u003cli\u003eThe application is rendered in an uninitialized state, allowing the attacker to re-configure the WordPress instance or achieve full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the permanent loss of arbitrary files on the server hosting the WordPress installation. In the context of WordPress, the deletion of 'wp-config.php' forces the application to revert to its initial setup state, facilitating remote code execution or complete takeover of the web application by unauthorized parties.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate removal or disabling of the WP File Download plugin until a vendor patch is applied to enforce capability and nonce validation. Monitor web server logs for high-frequency or unauthorized POST requests to 'admin-ajax.php' involving 'file.save' and 'file.delete' tasks.\u003c/p\u003e\n","date_modified":"2026-09-02T05:11:46Z","date_published":"2026-09-02T05:11:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-file-download-traversal/","summary":"The WP File Download plugin for WordPress contains a path traversal vulnerability in its file save and delete functions, allowing authenticated subscribers to delete arbitrary files on the server, potentially leading to remote code execution.","title":"Arbitrary File Deletion in WP File Download Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-file-download-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - WP File Download (All Versions)","version":"https://jsonfeed.org/version/1.1"}