CVE-2024-8699

The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Configurations

Configuration 1 (hide)

cpe:2.3:a:urbanbase:z-downloads:*:*:*:*:*:wordpress:*:*

History

28 May 2025, 15:42

Type Values Removed Values Added
First Time Urbanbase
Urbanbase z-downloads
CPE cpe:2.3:a:urbanbase:z-downloads:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/9013351e-224f-4696-970f-eb843dc8dace/ - () https://wpscan.com/vulnerability/9013351e-224f-4696-970f-eb843dc8dace/ - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo

20 May 2025, 20:15

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9013351e-224f-4696-970f-eb843dc8dace/ - () https://wpscan.com/vulnerability/9013351e-224f-4696-970f-eb843dc8dace/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

16 May 2025, 14:42

Type Values Removed Values Added
Summary
  • (es) El complemento Z-Downloads de WordPress anterior a la versión 1.11.5 no valida correctamente los archivos cargados, lo que permite que usuarios con privilegios elevados, como el administrador, carguen archivos arbitrarios en el servidor incluso cuando no deberían tener permiso para hacerlo (por ejemplo, en una configuración de varios sitios).

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-05-28 15:42


NVD link : CVE-2024-8699

Mitre link : CVE-2024-8699

CVE.ORG link : CVE-2024-8699


JSON object : View

Products Affected

urbanbase

  • z-downloads