CVE-2021-47940: WordPress Download From Files 1.48 Arbitrary File Upload
WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_from_files_617_fileupload action, manipulating the allowExt parameter to bypass file type restrictions and upload executable files like PHP shells to the web root.
Security readout for executives and security teams
Plain-English summary
A WordPress plugin called Download From Files (version 1.48 and earlier) has a flaw that lets anyone on the internet upload files to a site without logging in. Attackers can place a malicious file on the server, take control of the website, steal data, deface pages, or pivot deeper into hosting infrastructure. Any site running this plugin should treat it as an immediate concern.
Executive priority
Treat as high-priority within 24 to 48 hours for any site running this plugin. Unauthenticated remote code execution on a public WordPress site can lead to site takeover, customer-data exposure, SEO damage, and downstream incident-response costs. Removal of the plugin is the fastest risk reduction.
Technical view
The plugin exposes an unauthenticated AJAX action (download_from_files_617_fileupload) via admin-ajax.php. According to the public sources, the allowExt parameter is attacker-controlled, letting a remote, unauthenticated user bypass extension allowlists and write executable content such as PHP into web-accessible directories. CWE-306 (Missing Authentication) with CVSS 9.8 reflects the network-reachable, no-privilege, no-interaction path to full compromise.
Likely exposure
Any internet-facing WordPress site with the Download From Files plugin installed and active at version 1.48 or earlier is exposed. Exposure increases for sites that allow direct execution of files written into upload or plugin directories and that lack a WAF rule covering admin-ajax.php abuse.
Exploitation context
Public exploit code is indexed on Exploit-DB (entry 50287) and a third-party advisory exists at VulnCheck, indicating the technique is documented and trivially reproducible. The CVE is not currently listed in CISA KEV, so confirmed in-the-wild mass exploitation is not asserted by the bundled sources, but the low barrier and public PoC make opportunistic abuse plausible.
Researcher notes
CWE-306 with CVSS 9.8 (AV:N/AC:L/PR:N/UI:N) is consistent with the described unauthenticated AJAX path. Public PoC at Exploit-DB 50287 and VulnCheck advisory indicate the allowExt parameter governs the extension allowlist client-side, which the plugin trusts server-side. No fixed version is named in the bundled sources; confirm current plugin status on WordPress.org before assuming a patch exists.
Mitigation direction
Deactivate and delete the Download From Files plugin until vendor guidance confirms a fixed release.
Block unauthenticated POSTs to admin-ajax.php with action=download_from_files_617_fileupload at the WAF or edge.
Deny PHP execution inside wp-content/uploads and any plugin-writable directories.
Restrict wp-admin and admin-ajax.php access by IP allowlist where feasible.
Monitor vendor and WordPress.org plugin page for a patched version before reinstalling.
Validation and detection
Inventory WordPress sites and confirm whether download-from-files plugin is installed or active.
Check installed plugin version against 1.48 and earlier in wp-content/plugins/download-from-files.
Review web and access logs for POSTs to admin-ajax.php referencing the vulnerable action name.
Search upload and plugin directories for unexpected .php, .phtml, or double-extension files.
Validate WAF or edge rules block the vulnerable action with a benign synthetic request.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-306: Credential and account abuse lookup
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
2CVSS vectors
3Timeline events
1ADP providers
4Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
2 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-306 · source CWE mapping
Missing Authentication for Critical Function
Missing Authentication for Critical Function represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.