CVE-2026-66476
Received Received - Intake

Administrator Arbitrary File Deletion in Easy Digital Downloads

Vulnerability report for CVE-2026-66476, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Patchstack

Description

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
easy_digital_downloads easy_digital_downloads to 3.6.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated administrator or developer to delete arbitrary files on a WordPress site running Easy Digital Downloads plugin version 3.6.9 or lower. The flaw enables unauthorized file deletion which could disrupt website functionality by removing critical system or plugin files.

Detection Guidance

Check if the Easy Digital Downloads plugin version is 3.6.9 or below. If so, the system is vulnerable. No specific commands are provided in the context for detection.

Impact Analysis

An attacker with administrator access could delete essential website files, causing crashes, data loss, or complete site failure. Even with low severity, successful exploitation may lead to prolonged downtime and require costly recovery efforts.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves arbitrary file deletion requiring administrator privileges. However, unauthorized file deletion could lead to data loss or system unavailability, which may indirectly impact compliance if critical files (e.g., logs, records) are deleted.

Mitigation Strategies

Update the Easy Digital Downloads plugin to the latest version immediately. If no patch is available, disable the plugin temporarily or seek assistance from your hosting provider or web developer to mitigate the risk of arbitrary file deletion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66476. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart