CVE-2021-47940Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_from_files_617_fileupload action, manipulating the allowExt parameter to bypass file type restrictions and upload executable files like PHP shells to the web root.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-10: 2Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 205-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2021-47940 WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload maliciou… https://www.cve.org/CVERecord?id=CVE-2021-47940

    Post summary

    The post announces CVE-2021-47940 as an arbitrary file upload flaw in the WordPress Plugin Download From Files, enabling unauthenticated file uploads, without any PoC, exploit code, or patch information.

    0000073
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2021-47940 WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allo… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2021-47940 #WordPress #CyberSecurity #InfoSec

    Post summary

    The tweet reveals CVE‑2021‑47940 as an arbitrary file upload flaw with CVSS 9.8 and notes that no patch is currently available, but provides no PoC or exploit details.

    0000033
    90 followersView on X

Explore more