CVE-2021-47940 | download-from-files Download From Files up to 1.48 on WordPress AJAX File admin-ajax.php download_from_files_617_fileupload allowExt missing authentication (Exploit 50287 / EDB-50287)
A vulnerability, which was classified as critical, was found in download-from-files Download From Files up to 1.48 on WordPress. The impacted element is the function download_from_files_617_fileupload of the file admin-ajax.php of the component AJAX File Handler. The manipulation of the argument allowExt results in missing authentication.
This vulnerability is known as CVE-2021-47940. It is possible to launch the attack remotely. Furthermore, an exploit is available.