CVE-2024-8673
Z-Downloads < 1.11.7 - Admin+ Stored XSS via SVG Upload
Record summary
CVE-2024-8673 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Z-DownloadsDefault status: unaffected | CVE List | Before 1.11.7 | affected |
Nuclei templates
1ProjectDiscoveryLOWZ-Downloads < 1.11.7 - Cross-Site ScriptingCVSS 3.5
The plugin does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Impact
Authenticated attackers can upload SVG files containing malicious JavaScript that executes when other users view the uploaded files, potentially leading to session hijacking and data theft.
Remediation
Fixed in version 1.11.7
Source: ProjectDiscovery