CVE-2021-24960
07.03.2022, 09:15
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacksEnginsight
Vendor | Product | Version |
---|---|---|
iptanus | wordpress_file_upload | 𝑥 < 4.16.3 |
iptanus | wordpress_file_upload_pro | 𝑥 < 4.16.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration