cleantalk
Vulnerabilities and Security Researches

Z-Downloads, CVE-2024-8699

CVE, Research URL

CVE-2024-8699

Application

Z-Downloads

Published on
May 16, 2025
Research Description
The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Affected versions
Min -, max 1.11.5.
Status
vulnerable