Z-Downloads WordPress Plugin File Upload Vulnerability Allowing Malicious SVGs

Vulnerability

A vulnerability exists in the Z-Downloads WordPress plugin in versions prior to 1.11.7, where the plugin fails to properly validate uploaded files. This flaw allows users to upload SVG files containing harmful JavaScript.

Impact

Exploitation of this vulnerability could lead to stored cross-site scripting, where uploaded SVGs with embedded JavaScript are executed in the context of the user viewing the download.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
6.0
remediation
7.7
relevance
0.0
threat
6.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.