cleantalk
Vulnerabilities and Security Researches

Z-Downloads, CVE-2024-8673

CVE, Research URL

CVE-2024-8673

Application

Z-Downloads

Published on
May 16, 2025
Research Description
The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Affected versions
Min -, max 1.11.7.
Status
vulnerable