Zurück zu den Sicherheitshinweisen

Paid Downloads for WordPress CVE-2026-87935: Arbitrary File Upload

Paid Downloads plugin for WordPress is affected by CVE-2026-87935. The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization. Affected versions: all versions up to and including 3.15. CVSS base score: 8.1.

High 8.1 CVSS
WordPress

Betroffene Versionen

all versions up to and including 3.15

Standard-Update-Befehl

wp plugin update

Fix-Befehle

All supported operating systems

# Update the Paid Downloads plugin to the latest WordPress.org release
wp plugin update --all

Was das unter einer SharedLicense-Lizenz bedeutet

Your SharedLicense license itself is not affected — this is a vulnerability in Paid Downloads plugin for WordPress (a free WordPress plugin), not in licensing. No license action is needed; update the plugin to protect the sites running on your servers.

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. On Apache servers where AllowOverride is enabled, an .htaccess file placed in the upload directory may block direct HTTP retrieval of uploaded files, limiting exploitability to stacks that do not honor .htaccess directives such as nginx, LiteSpeed, and Apache with AllowOverride None.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-87935

Häufig gestellte Fragen

What is CVE-2026-87935?
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization. Affected versions: all versions up to and including 3.15.
Is CVE-2026-87935 being exploited in the wild?
No confirmed public exploitation has been announced at the time of writing. With a CVSS base score of 8.1, apply the update on your next maintenance window and watch the vendor advisory for changes.
How do I fix CVE-2026-87935?
Update the Paid Downloads plugin to the latest WordPress.org release. wp plugin update --all.
Which versions are affected?
Affected: all versions up to and including 3.15. Update to the latest release.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen