CVE-2026-87935
Last modified
CVE-2026-87935 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. On Apache servers where AllowOverride is enabled, an .htaccess file placed in the upload directory may block direct HTTP retrieval of uploaded files, limiting exploitability to stacks that do not honor .htaccess directives such as nginx, LiteSpeed, and Apache with AllowOverride None.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ichurakov | Paid Downloads | <= 3.15 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-87935?
How severe is CVE-2026-87935?
How do I fix CVE-2026-87935?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-87928MaxSite CMS versions 0.94 through 109.6 contain a cross-site…5.4
- CVE-2026-87929MaxSite CMS through 109.6 ships with a hardcoded session enc…9.8
- CVE-2026-8793PaperCut NG/MF does not properly restrict excessive authenti…6.9
- CVE-2026-87930MaxSite CMS through 109.6 passes the ci_session cookie to un…8.1
- CVE-2026-87931A vulnerability has been found in Behavioral Technology Grou…9.6
- CVE-2026-87933A vulnerability was found in DaveGamble cJSON up to 1.7.19. …7.3
- CVE-2026-8794PaperCut NG/MF contains an observable timing discrepancy in …6.9
- CVE-2026-8795A YAML injection vulnerability exists in the Windows.Collect…7.8
- CVE-2026-87958IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is …8.1
- CVE-2026-87959The WPBot WordPress plugin before 8.7.6 does not perform a …5.4
- CVE-2026-8796Sereal::Decoder versions before 5.005 for Perl allow heap ou…8.1
- CVE-2026-87961ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-b…7.1
Are you affected by CVE-2026-87935?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
