CVE-2024-13544

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:amini7:zarinpal_paid_download:*:*:*:*:*:wordpress:*:*

History

20 Feb 2025, 16:11

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/91884263-62a7-436e-b19f-682b1aeb37d6/ - () https://wpscan.com/vulnerability/91884263-62a7-436e-b19f-682b1aeb37d6/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:amini7:zarinpal_paid_download:*:*:*:*:*:wordpress:*:*
CWE CWE-434
Summary
  • (es) El complemento Zarinpal Paid Download WordPress hasta la versión 2.3 no valida correctamente los archivos cargados, lo que permite que usuarios con privilegios elevados, como el administrador, carguen archivos arbitrarios en el servidor incluso cuando no se les debería permitir hacerlo (por ejemplo, en una configuración de varios sitios).
First Time Amini7 zarinpal Paid Download
Amini7

11 Feb 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

11 Feb 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 06:15

Updated : 2025-02-20 16:11


NVD link : CVE-2024-13544

Mitre link : CVE-2024-13544

CVE.ORG link : CVE-2024-13544


JSON object : View

Products Affected

amini7

  • zarinpal_paid_download
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type