Z-Downloads
cpe:2.3:a:urbanbase:z-downloads:*:*:*:*:wordpress:*:*
- < 1.11.5
A vulnerability exists in the Z-Downloads WordPress plugin in versions prior to 1.11.5, where the plugin fails to properly validate uploaded files. This flaw allows high-privilege users, such as administrators, to upload arbitrary files to the server, even in situations where such actions should be restricted, like in a multisite environment.
Exploitation of this vulnerability could lead to unauthorized file uploads, potentially allowing for further actions such as executing uploaded files if the server is configured to do so.
Users are advised to update the Z-Downloads WordPress plugin to version 1.11.5 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.