CVE-2021-47940
published 2026-05-10CVE-2021-47940: WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
31.4th percentile
WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_from_files_617_fileupload action, manipulating the allowExt parameter to bypass file type restrictions and upload executable files like PHP shells to the web root.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| download-from-files | download_from_files | <= 1.48 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h4p-vqhv-pvp3: WordPress Plugin Download From Files version 1
ghsa_unreviewed·2026-05-10
CVE-2021-47940 [CRITICAL] CWE-306 GHSA-8h4p-vqhv-pvp3: WordPress Plugin Download From Files version 1
WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_from_files_617_fileupload action, manipulating the allowExt parameter to bypass file type restrictions and upload executable files like PHP shells to the web root.
VulDB
download-from-files Download From Files up to 1.48 on WordPress AJAX File admin-ajax.php download_from_files_617_fileupload allowExt missing authentication (Exploit 50287 / EDB-50287)
vuldb·2026-05-10·CVSS 9.3
CVE-2021-47940 [CRITICAL] download-from-files Download From Files up to 1.48 on WordPress AJAX File admin-ajax.php download_from_files_617_fileupload allowExt missing authentication (Exploit 50287 / EDB-50287)
A vulnerability, which was classified as critical, was found in download-from-files Download From Files up to 1.48 on WordPress. The impacted element is the function download_from_files_617_fileupload of the file admin-ajax.php of the component AJAX File Handler. The manipulation of the argument allowExt results in missing authentication.
This vulnerability is known as CVE-2021-47940. It is possible to launch the attack remotely. Furthermore, an exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-10
Published