PT-2025-6159 · WordPress · Zarinpal Paid Download

Bob Matyas

·

Published

2025-02-11

·

Updated

2025-02-20

·

CVE-2024-13544

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Zarinpal Paid Download WordPress plugin versions prior to 2.4
Description: The issue arises from the plugin's failure to properly validate uploaded files, allowing high-privilege users, such as administrators, to upload arbitrary files to the server. This can occur even in scenarios where such uploads should be restricted, such as in multisite setups.
Recommendations: For versions prior to 2.4, update to version 2.4 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities for high-privilege users until a patch is available.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-13544

Affected Products

Zarinpal Paid Download