The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Affected Software
| Name | 
Vendor | 
Start Version | 
End Version | 
| Z-downloads | 
Urbanbase | 
* | 
1.11.7 (excluding) | 
References