CVE-2024-8673

Publication date

2025-05-15 20:07:17

Family

WPScan

State

PUBLISHED

Description

The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.