Record summary

CVE-2024-8673 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Z-Downloads

Default status: unaffected

CVE ListBefore 1.11.7affected

Nuclei templates

1
ProjectDiscoveryLOWZ-Downloads < 1.11.7 - Cross-Site ScriptingCVSS 3.5

The plugin does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.

Impact

Authenticated attackers can upload SVG files containing malicious JavaScript that executes when other users view the uploaded files, potentially leading to session hijacking and data theft.

Remediation

Fixed in version 1.11.7

WeaknessesCWE-79
AuthorsSplint3r7
Template tagscvecve2024wpscanwp-pluginwpauthenticatedwordpressz-downloadsvuln

Source: ProjectDiscovery

References

2