CVE-2024-13544

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:amini7:zarinpal_paid_download:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2025-02-11 06:15

Updated : 2025-02-20 16:11


NVD link : CVE-2024-13544

Mitre link : CVE-2024-13544

CVE.ORG link : CVE-2024-13544


JSON object : View

Products Affected

amini7

  • zarinpal_paid_download
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type