PT-2023-30734 · WordPress · Drag/Drop Multiple File Upload

Zeyad Alshahrani

·

Publicado

2023-10-16

·

Atualizado

2023-10-20

·

CVE-2023-4821

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drag and Drop Multiple File Upload for WooCommerce WordPress plugin versions prior to 1.1.1
Description The issue allows an attacker to upload unsafe files, including .shtml or .svg files, which can contain malicious scripts. This is due to the plugin not filtering all potentially dangerous file extensions.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to only trusted users or disabling the file upload feature until the update is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-4821

Produtos afetados

Drag/Drop Multiple File Upload