CVE · High

CVE-2026-12476 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12476 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.9.1 Unrestricted Upload of File with Dangerous Type High 7.2 < 3.6.9.1 3.6.9.1 2026-07-28

CVE-2026-12476

The Easy Digital Downloads plugin for WordPress, in versions up to 3.6.9, has a vulnerability that allows authenticated attackers with sufficient access to upload files of any type to the server. This is because the plugin doesn't properly check the types of files being uploaded, allowing malicious files to be written to a directory that can be accessed from the web. As a result, attackers may be able to execute code remotely on the affected site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.