What is CVE-2026-18933?
This CVE describes a vulnerability in the wp-downloadmanager WordPress plugin where an admin-level user can upload arbitrary files via download-add.php without any file extension or MIME-type validation. It affects versions 1.68.11 and the 6.9.4 release line. This could lead to remote code execution, so immediate plugin update is recommended.
Azərbaycanca: Bu CVE, wp-downloadmanager WordPress plaginində admin səlahiyyətli istifadəçiyə heç bir fayl uzantısı və ya MIME-tip yoxlaması olmadan ixtiyari fayl yükləməyə imkan verən boşluqdur. Təsirə məruz qalan versiyalar 1.68.11 və 6.9.4 buraxılış xəttidir. Bu zəiflik uzaqdan kod icrasına səbəb ola bilər, ona görə də plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
What user level does CVE-2026-18933 affect in the wp-downloadmanager plugin?
This vulnerability affects admin-level users.
What should be done to protect against CVE-2026-18933?
The plugin should be updated to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.