CVE-2026-12476

Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header against an allow-list of CSV mime types, then uses raw move_uploaded_file() (bypassing wp_handle_upload()'s core MIME enforcement) to write the file under its original extension into the web-accessible wp-content/uploads/edd/exports/ directory. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 13,023 live websites that are affected by CVE-2026-12476.

Run a Free Instant Scan




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Domains13,023 live websites (100% of Easy Digital Downloads install base)
Vulnerable Versions
  • from 0 through 3.6.9
Vulnerable Versions Count151 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Jul 29, 2026
  • Updated - Jul 29, 2026

Credits

  • Tal Kantor (finder)

Website Distribution by Country

Number of websites using CVE-2026-12476
United States6,442 websites



Germany1,037 websites
GB730 websites
Iran545 websites
France514 websites
Italy387 websites
Cyprus336 websites
Canada249 websites
Japan232 websites
Australia225 websites

Website Distribution by TLD

Number of websites using CVE-2026-12476
.com8,065 websites
.org765 websites
.net439 websites
.de328 websites
.co.uk314 websites
.it248 websites
.com.au172 websites
.nl161 websites
.fr158 websites
.ca108 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12476

Top websites that are affected by CVE-2026-12476. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***********.com United States*,***
***************.eu Netherlands*,***
********.com Germany*,***
**************.com Canada*,***
**********.com United States*,***
********.com United States*,***
************.com United States*,***
**********.com United States*,***
*************.com United States*,***
See full domain list

FAQ

CVE-2026-12476 is Unrestricted Upload of File with Dangerous Type in Easy Digital Downloads
A total of 13,023 websites have been identified as vulnerable to CVE-2026-12476, based on global website indexing conducted by WebTechSurvey.
The Easy Digital Downloads is affected by the CVE-2026-12476 vulnerability.
Easy Digital Downloads versions up to and including 3.6.9 are vulnerable to CVE-2026-12476.

References