Z-Downloads
cpe:2.3:a:urbanbase:z-downloads:*:*:*:*:wordpress:*:*
- < 1.11.7
A vulnerability exists in the Z-Downloads WordPress plugin in versions prior to 1.11.7, where the plugin fails to properly validate uploaded files. This flaw allows users to upload SVG files containing harmful JavaScript.
Exploitation of this vulnerability could lead to stored cross-site scripting, where uploaded SVGs with embedded JavaScript are executed in the context of the user viewing the download.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.