Mehrere Schwachstellen (CVE-2021-47932, CVE-2021-47933, CVE-2021-47936, CVE-2021-47940, CVE-2026-42601) in Wordpress

WordPress - Download From Files - CRITICAL - CVE-2021-47940. The Download From Files plugin for WordPress, up to version 1.48, is vulnerable to an arbitrary file upload issue that can be exploited by unauthenticated attackers. By sending POST requests to the admin-ajax.php endpoint with specifically crafted payloads, attackers can manipulate the allowExt parameter to bypass standard file type restrictions. This enables them to upload malicious files, including executable scripts such as PHP shells, directly to the web root, posing significant security risks for affected websites. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io