PT-2025-21529 · WordPress · Z-Downloads
Bob Matyas
·
Published
2025-05-15
·
Updated
2025-05-28
·
CVE-2024-8673
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Z-Downloads versions prior to 1.11.7
Description:
The issue concerns the Z-Downloads WordPress plugin, which does not properly validate uploaded files. This allows for the uploading of SVG files that contain malicious JavaScript.
Recommendations:
For versions prior to 1.11.7, update to version 1.11.7 or later to resolve the issue. As a temporary workaround, consider restricting the upload of SVG files or disabling the file upload feature until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Z-Downloads