Paid Downloads for WordPress CVE-2026-87935: Arbitrary File Upload
Paid Downloads plugin for WordPress is affected by CVE-2026-87935. The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization. Affected versions: all versions up to and including 3.15. CVSS base score: 8.1.
Affected Versions
all versions up to and including 3.15
Default Update CMD
wp plugin update
Fix Commands
All supported operating systems
# Update the Paid Downloads plugin to the latest WordPress.org release
wp plugin update --all
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a vulnerability in Paid Downloads plugin for WordPress (a free WordPress plugin), not in licensing. No license action is needed; update the plugin to protect the sites running on your servers.
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. On Apache servers where AllowOverride is enabled, an .htaccess file placed in the upload directory may block direct HTTP retrieval of uploaded files, limiting exploitability to stacks that do not honor .htaccess directives such as nginx, LiteSpeed, and Apache with AllowOverride None.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-87935
Frequently Asked Questions
What is CVE-2026-87935?
Is CVE-2026-87935 being exploited in the wild?
How do I fix CVE-2026-87935?
Which versions are affected?
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System