CVE-2021-47940
WordPress plugin allows attackers to upload malicious files to take control.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
WordPress plugin Download From Files allows unauthenticated attackers to upload malicious files, potentially leading to server compromise. This critical flaw is internet-facing and affects websites using version 1.48 and earlier.