VULNERABILITY INTELLIGENCE
CVE-2024-8699
CVSS score7.2 HIGH
EPSS probability0.70%
CISA KEVNot currently listed
Published2025-05-15
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Primary references
- contact@wpscan.com — Exploit, Third Party Advisory
- 134c704f-9b21-4f2e-91b3-4a467353bcc0 — Exploit, Third Party Advisory