Impact
The Paid Downloads plugin contains an arbitrary file upload flaw due to missing authorization and file type validation in the admin_request_handler function. Because is_admin() returns true for /wp-admin/admin-post.php, the upload endpoint is reachable without authentication, allowing an attacker to place executable files on the server and achieve remote code execution.
Affected Systems
All installations of the ichurakov Paid Downloads WordPress plugin up to and including version 3.15 are vulnerable. No specific build or package distinctions are noted beyond the version limit.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1 and an EPSS score of less than 1 %, indicating low exploitation probability, and it is not listed in the CISA KEV catalog. Nevertheless, because the upload vector is unrestricted and can inject arbitrary code, the risk remains significant for sites that allow the plugin to run. An exploit can be performed from any network location that can reach the site’s admin-post endpoint; the attack does not require authenticated credentials. Server configurations that honor Apache’s AllowOverride may block HTTP retrieval of the uploaded file via an .htaccess file, but this does not prevent code execution if the file is executed by the server in other ways.
OpenCVE Enrichment