CVE Database /
CVE-2026-12476
CVE · High
CVE-2026-12476 — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.9.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12476
|
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.9.1 |
Unrestricted Upload of File with Dangerous Type |
High
7.2
|
< 3.6.9.1
|
3.6.9.1 |
2026-07-28 |
—
|
CVE-2026-12476
The Easy Digital Downloads plugin for WordPress, in versions up to 3.6.9, has a vulnerability that allows authenticated attackers with sufficient access to upload files of any type to the server. This is because the plugin doesn't properly check the types of files being uploaded, allowing malicious files to be written to a directory that can be accessed from the web. As a result, attackers may be able to execute code remotely on the affected site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings