Vulnerability Description
The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amini7 | Zarinpal Paid Download | <= 2.3 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/91884263-62a7-436e-b19f-682b1aeb37d6/ExploitThird Party Advisory
FAQ
What is CVE-2024-13544?
CVE-2024-13544 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they sh...
How severe is CVE-2024-13544?
CVE-2024-13544 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-13544?
Check the references section above for vendor advisories and patch information. Affected products include: Amini7 Zarinpal Paid Download.