CVE-2026-32536: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32536 is an Unrestricted File Upload vulnerability (CWE-434) in the Green Downloads WordPress plugin by halfdata, affecting all versions up to and including 2.08. It allows authenticated attackers with low privileges (Subscriber-level) to upload malicious files without proper type validation, potentially enabling remote code execution. The vulnerability was reported by researcher Phat RiO on January 31, 2026, and publicly disclosed on March 20–25, 2026. It carries a CVSS v3.1 base score of 9.9 (Critical) (Patchstack, Feedly).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the Green Downloads plugin fails to properly validate the type or content of uploaded files on the server side, allowing dangerous file types (e.g., PHP web shells) to be uploaded and subsequently executed. The attack vector is network-based, requires low privileges (Subscriber-level authentication), no user interaction, and has low attack complexity. The CVSS scope is marked as "Changed," indicating the vulnerability can affect resources beyond the plugin component itself — including the broader WordPress installation and underlying server. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with minimal privileges to upload and execute arbitrary malicious files (e.g., PHP backdoors or web shells) on the affected WordPress server. This can result in full compromise of confidentiality, integrity, and availability of the WordPress installation and potentially the underlying host system. Because the CVSS scope is "Changed," the impact can extend beyond the plugin itself to other hosted sites, databases, and server resources, enabling lateral movement, data exfiltration, and persistent access (Patchstack, Feedly).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.042% (0.000420), indicating a currently low probability of exploitation in the near term. However, Patchstack notes that vulnerabilities of this severity class (CVSS 9.9, arbitrary file upload) are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. No threat actor attribution or CISA KEV catalog listing has been identified (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Green Downloads plugin (halfdata-paypal-green-downloads) version ≤ 2.08 using tools like WPScan, Shodan, or Google dorks (e.g., inurl:/wp-content/plugins/halfdata-paypal-green-downloads).
  2. Obtain low-privilege credentials: Register or obtain a Subscriber-level (or equivalent low-privilege) WordPress account on the target site.
  3. Locate the file upload endpoint: Navigate to the plugin's file upload functionality within the WordPress interface (e.g., a download submission or file management form exposed by the plugin).
  4. Craft a malicious payload: Prepare a PHP web shell or backdoor file (e.g., shell.php containing <?php system($_GET['cmd']); ?>).
  5. Upload the malicious file: Submit the PHP file through the plugin's upload feature. Due to the lack of server-side file type validation, the upload succeeds without restriction.
  6. Execute the payload: Determine the upload directory path (commonly /wp-content/uploads/ or a plugin-specific subdirectory) and access the uploaded file via HTTP (e.g., https://target.com/wp-content/uploads/shell.php?cmd=id) to achieve remote code execution (Patchstack).

Indicators of compromise

  • File System: Unexpected .php files (e.g., shell.php, cmd.php, upload.php) in WordPress upload directories such as /wp-content/uploads/ or plugin-specific subdirectories; newly created files with obfuscated or encoded PHP code.
  • Logs: Web server access logs showing POST requests to plugin upload endpoints followed by GET requests to .php files in upload directories; unusual HTTP 200 responses for PHP files in /wp-content/uploads/.
  • Network: Outbound connections from the web server process to unknown external IPs (indicative of reverse shells or C2 communication); unusual DNS lookups originating from the web server.
  • Process: Unexpected child processes spawned by the web server (e.g., Apache/Nginx/PHP-FPM) such as bash, curl, wget, python, or perl; new cron jobs or scheduled tasks created under the web server user account.

Mitigation and workarounds

The vendor has released version 2.09 of the Green Downloads plugin, which patches this vulnerability — update immediately via the WordPress plugin dashboard or manually (Patchstack). If an immediate update is not possible, restrict file upload functionality to trusted administrator-level users only, and implement server-side file type validation (checking MIME type and file content, not just extension). Additionally, configure the web server to deny PHP execution within upload directories (e.g., via .htaccess rules), and consider disabling the plugin entirely until patching is feasible. Patchstack users benefit from a virtual patch/mitigation rule that blocks exploitation attempts without requiring an immediate plugin update.

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability intelligence report for the week of March 16–22, 2026, highlighting it as a notable high-severity issue (Wordfence Blog). The Hacker Wire covered the disclosure, noting the critical nature of the unrestricted file upload flaw (The Hacker Wire). Tanzania's national CERT (TZCERT) issued a security advisory (TZCERT-SA-26-0137) urging affected site operators to update promptly (TZCERT).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management