CVE-2024-13544

MEDIUM

Zarinpal Paid Download < 2.3 - Authenticated Arbitrary File Upload

Title source: llm
STIX 2.1

Description

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/91884263-62a7-436e-b19f-682b1aeb37d6/

Scores

CVSS v3 4.8
EPSS 0.0031
EPSS Percentile 22.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
amini7/zarinpal_paid_download < 2.3
Published Feb 11, 2025
Tracked Since Feb 18, 2026