CVE-2024-8703: Z-Downloads < 1.11.6 - Unauthenticated Stored XSS

Description

The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.

Classification

CVE ID: CVE-2024-8703

Problem Types

CWE-79 Cross-Site Scripting (XSS)

Affected Products

Vendor: Unknown

Product: Z-Downloads

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 6.76% (scored less or equal to compared to others)

EPSS Date: 2025-06-04 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-8703
https://wpscan.com/vulnerability/604e990e-9bec-469e-8630-605eea74e12c/

Timeline