CVE-2024-8699

HIGH

Z-Downloads WP <1.11.5 - Privilege Escalation

Title source: llm

Description

The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

Exploits (1)

github WORKING POC 3 stars
by certuscyber · pythonpoc
https://github.com/certuscyber/cve-pocs/tree/main/CVE-2024-8699

Scores

CVSS v3 7.2
EPSS 0.0085
EPSS Percentile 75.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
urbanbase/z-downloads < 1.11.5
Published May 15, 2025
Tracked Since Feb 18, 2026