CVE-2024-13544

MEDIUM

Amini7 Zarinpal Paid Download < 2.3 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/91884263-62a7-436e-b19f-682b1aeb37d6/

Scores

CVSS v3 4.8
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
amini7/zarinpal_paid_download < 2.3
Published Feb 11, 2025
Tracked Since Feb 18, 2026