The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Z-downloads | Urbanbase | * | 1.11.7 (excluding) |
References