
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32536 is an Unrestricted File Upload vulnerability (CWE-434) in the Green Downloads WordPress plugin by halfdata, affecting all versions up to and including 2.08. It allows authenticated attackers with low privileges (Subscriber-level) to upload malicious files without proper type validation, potentially enabling remote code execution. The vulnerability was reported by researcher Phat RiO on January 31, 2026, and publicly disclosed on March 20–25, 2026. It carries a CVSS v3.1 base score of 9.9 (Critical) (Patchstack, Feedly).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the Green Downloads plugin fails to properly validate the type or content of uploaded files on the server side, allowing dangerous file types (e.g., PHP web shells) to be uploaded and subsequently executed. The attack vector is network-based, requires low privileges (Subscriber-level authentication), no user interaction, and has low attack complexity. The CVSS scope is marked as "Changed," indicating the vulnerability can affect resources beyond the plugin component itself — including the broader WordPress installation and underlying server. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an authenticated attacker with minimal privileges to upload and execute arbitrary malicious files (e.g., PHP backdoors or web shells) on the affected WordPress server. This can result in full compromise of confidentiality, integrity, and availability of the WordPress installation and potentially the underlying host system. Because the CVSS scope is "Changed," the impact can extend beyond the plugin itself to other hosted sites, databases, and server resources, enabling lateral movement, data exfiltration, and persistent access (Patchstack, Feedly).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.042% (0.000420), indicating a currently low probability of exploitation in the near term. However, Patchstack notes that vulnerabilities of this severity class (CVSS 9.9, arbitrary file upload) are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No threat actor attribution or CISA KEV catalog listing has been identified (Patchstack, Feedly).
inurl:/wp-content/plugins/halfdata-paypal-green-downloads).shell.php containing <?php system($_GET['cmd']); ?>)./wp-content/uploads/ or a plugin-specific subdirectory) and access the uploaded file via HTTP (e.g., https://target.com/wp-content/uploads/shell.php?cmd=id) to achieve remote code execution (Patchstack)..php files (e.g., shell.php, cmd.php, upload.php) in WordPress upload directories such as /wp-content/uploads/ or plugin-specific subdirectories; newly created files with obfuscated or encoded PHP code..php files in upload directories; unusual HTTP 200 responses for PHP files in /wp-content/uploads/.bash, curl, wget, python, or perl; new cron jobs or scheduled tasks created under the web server user account.The vendor has released version 2.09 of the Green Downloads plugin, which patches this vulnerability — update immediately via the WordPress plugin dashboard or manually (Patchstack). If an immediate update is not possible, restrict file upload functionality to trusted administrator-level users only, and implement server-side file type validation (checking MIME type and file content, not just extension). Additionally, configure the web server to deny PHP execution within upload directories (e.g., via .htaccess rules), and consider disabling the plugin entirely until patching is feasible. Patchstack users benefit from a virtual patch/mitigation rule that blocks exploitation attempts without requiring an immediate plugin update.
Wordfence included this vulnerability in their weekly WordPress vulnerability intelligence report for the week of March 16–22, 2026, highlighting it as a notable high-severity issue (Wordfence Blog). The Hacker Wire covered the disclosure, noting the critical nature of the unrestricted file upload flaw (The Hacker Wire). Tanzania's national CERT (TZCERT) issued a security advisory (TZCERT-SA-26-0137) urging affected site operators to update promptly (TZCERT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."