The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
History

Wed, 28 May 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Urbanbase
Urbanbase z-downloads
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:urbanbase:z-downloads:*:*:*:*:*:wordpress:*:*
Vendors & Products Urbanbase
Urbanbase z-downloads

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Title Z-Downloads < 1.11.5 - Admin+ Arbitrary File Upload
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:17.630Z

Updated: 2025-05-20T19:13:07.894Z

Reserved: 2024-09-11T13:09:13.528Z

Link: CVE-2024-8699

cve-icon Vulnrichment

Updated: 2025-05-19T20:24:08.697Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:59.467

Modified: 2025-05-28T15:42:01.943

Link: CVE-2024-8699

cve-icon Redhat

No data.