← Back

CVE-2024-13544

nvd nist
Published: Feb 11, 2025Modified: Feb 20, 2025

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

Affected (1)

1 product
Zarinpal Paid Download
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.3

References (1)

Source: contact@wpscan.com
ExploitThird Party Advisory

Timeline

No history available yet.