CVE-2024-8699
HIGHZ-Downloads WP <1.11.5 - Privilege Escalation
Title source: llmDescription
The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Exploits (1)
github
WORKING POC
3 stars
by certuscyber · pythonpoc
https://github.com/certuscyber/cve-pocs/tree/main/CVE-2024-8699
Scores
CVSS v3
7.2
EPSS
0.0085
EPSS Percentile
75.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
urbanbase/z-downloads
< 1.11.5
Published
May 15, 2025
Tracked Since
Feb 18, 2026