Ichurakov Paid Downloads vulnerabilities
2 known vulnerabilities affecting ichurakov/paid_downloads.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2025-68857P2CRITICALCVSS 9.3≤ 3.152026-01-22
CVE-2025-68857 [CRITICAL] CWE-89 CVE-2025-68857: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Downloads paid-downloads allows Blind SQL Injection.This issue affects Paid Downloads: from n/a through <= 3.15.
nvd
CVE-2026-87935P2HIGHCVSS 8.1≤ 3.152026-09-17
CVE-2026-87935 [HIGH] CWE-434 CVE-2026-87935: The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.
nvd