CVE-2021-47940 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: May 10, 2026
WordPress Plugin Download From Files - Unrestricted File Upload
Published: May 10, 2026Updated: May 10, 2026Remote Exploitable
Overview
WordPress Plugin Download From Files <= 1.48 contains an unrestricted file upload vulnerability caused by improper validation of the allowExt parameter in AJAX fileupload action, letting unauthenticated attackers upload malicious executable files to the web root.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Unauthenticated attackers can upload malicious executable files, potentially leading to remote code execution and full server compromise.
Mitigation
Update to the latest version of the plugin.
References
Related Resources
Details
- CVE ID
- CVE-2021-47940
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- unrestricted_file_upload
- Status
- new
CWE
- CWE-306
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H