Z-Downloads < 1.11.5 - Admin+ Arbitrary File Upload
Description
The Z-Downloads WordPress plugin before 1.11.5 allows high-privilege users to upload arbitrary files, bypassing intended restrictions in multisite setups.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Z-Downloads WordPress plugin before 1.11.5 allows high-privilege users to upload arbitrary files, bypassing intended restrictions in multisite setups.
Vulnerability
The Z-Downloads WordPress plugin before version 1.11.5 fails to properly validate uploaded files, allowing high-privilege users such as administrators to upload arbitrary file types to the server. This bypasses intended restrictions, particularly in multisite configurations where such uploads should be limited [1].
Exploitation
An attacker with administrator-level access can exploit this vulnerability by uploading a malicious file (e.g., a PHP web shell) through the plugin's file upload functionality. No additional user interaction is required beyond the attacker's own actions [1].
Impact
Successful exploitation enables the attacker to upload arbitrary files, potentially leading to remote code execution if a web shell is uploaded. This can result in full site compromise, including data theft, defacement, or further lateral movement within the server environment. In multisite setups, the vulnerability undermines intended privilege restrictions [1].
Mitigation
The vulnerability is fixed in version 1.11.5 of the Z-Downloads plugin. Users should update to this version immediately. No workarounds are documented, and the issue is not listed on CISA's Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <1.11.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/9013351e-224f-4696-970f-eb843dc8dace/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.