Security Advisory

CVE-2024-8673

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-05-15 20:07:17
Last updated 2025-05-20 19:25:26
Assigner WPScan
State PUBLISHED

Description

The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.