PT-2025-21529 · WordPress · Z-Downloads

·

CVE-2024-8673

·

Published

2025-05-15

·

Updated

2025-05-28

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Z-Downloads versions prior to 1.11.7
Description: The issue concerns the Z-Downloads WordPress plugin, which does not properly validate uploaded files. This allows for the uploading of SVG files that contain malicious JavaScript.
Recommendations: For versions prior to 1.11.7, update to version 1.11.7 or later to resolve the issue. As a temporary workaround, consider restricting the upload of SVG files or disabling the file upload feature until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-8673

Affected Products

Z-Downloads