Vulnerability Details CVE-2024-8673
The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 88.3%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2024-8673
-
cpe:2.3:a:urbanbase:z-downloads:1.0.0
-
cpe:2.3:a:urbanbase:z-downloads:1.0.1
-
cpe:2.3:a:urbanbase:z-downloads:1.1.0
-
cpe:2.3:a:urbanbase:z-downloads:1.10.0
-
cpe:2.3:a:urbanbase:z-downloads:1.10.1
-
cpe:2.3:a:urbanbase:z-downloads:1.10.2
-
cpe:2.3:a:urbanbase:z-downloads:1.11.0
-
cpe:2.3:a:urbanbase:z-downloads:1.11.1
-
cpe:2.3:a:urbanbase:z-downloads:1.11.2
-
cpe:2.3:a:urbanbase:z-downloads:1.11.3
-
cpe:2.3:a:urbanbase:z-downloads:1.11.4
-
cpe:2.3:a:urbanbase:z-downloads:1.11.5
-
cpe:2.3:a:urbanbase:z-downloads:1.11.6
-
cpe:2.3:a:urbanbase:z-downloads:1.2.0
-
cpe:2.3:a:urbanbase:z-downloads:1.3.0
-
cpe:2.3:a:urbanbase:z-downloads:1.4.0
-
cpe:2.3:a:urbanbase:z-downloads:1.4.1
-
cpe:2.3:a:urbanbase:z-downloads:1.4.2
-
cpe:2.3:a:urbanbase:z-downloads:1.5.0
-
cpe:2.3:a:urbanbase:z-downloads:1.5.1
-
cpe:2.3:a:urbanbase:z-downloads:1.5.2
-
cpe:2.3:a:urbanbase:z-downloads:1.6.0
-
cpe:2.3:a:urbanbase:z-downloads:1.6.1
-
cpe:2.3:a:urbanbase:z-downloads:1.7.0
-
cpe:2.3:a:urbanbase:z-downloads:1.7.1
-
cpe:2.3:a:urbanbase:z-downloads:1.7.2
-
cpe:2.3:a:urbanbase:z-downloads:1.7.4
-
cpe:2.3:a:urbanbase:z-downloads:1.8.0
-
cpe:2.3:a:urbanbase:z-downloads:1.8.1
-
cpe:2.3:a:urbanbase:z-downloads:1.8.2
-
cpe:2.3:a:urbanbase:z-downloads:1.9.0
-
cpe:2.3:a:urbanbase:z-downloads:1.9.1
-
cpe:2.3:a:urbanbase:z-downloads:1.9.2