CVE-2026-87935 | ichurakov Paid Downloads Plugin up to 3.15 on WordPress /wp-admin/admin-post.php admin_request_handler unrestricted upload (EUVD-2026-81334)

SecurityVulns

A vulnerability described as critical has been identified in ichurakov Paid Downloads Plugin up to 3.15 on WordPress. Affected is the function admin_request_handler of the file /wp-admin/admin-post.php. Executing a manipulation can lead to unrestricted upload.

This vulnerability is handled as CVE-2026-87935. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More