logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-13544

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-13544

Description:
The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Last updated date:
02/20/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/20/2025
Reference url to background

https://wpscan.com/vulnerability/91884263-62a7-436e-b19f-682b1aeb37d6/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy