The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Z-downloads |
Urbanbase |
* |
1.11.7 (excluding) |
References