LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2021-47940

CVE-2021-47940 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: May 10, 2026

WordPress Plugin Download From Files - Unrestricted File Upload

Published: May 10, 2026Updated: May 10, 2026Remote Exploitable

Overview

WordPress Plugin Download From Files <= 1.48 contains an unrestricted file upload vulnerability caused by improper validation of the allowExt parameter in AJAX fileupload action, letting unauthenticated attackers upload malicious executable files to the web root.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Unauthenticated attackers can upload malicious executable files, potentially leading to remote code execution and full server compromise.

Mitigation

Update to the latest version of the plugin.

Details

CVE ID
CVE-2021-47940
Severity
Critical
CVSS Score
9.8
Type
unrestricted_file_upload
Status
new

CWE

  • CWE-306

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H