PT-2021-16082 · WordPress · Frontend Uploader
Veshraj Ghimire
+1
·
Published
2021-10-11
·
Updated
2022-02-19
·
CVE-2021-24563
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frontend Uploader WordPress plugin versions 1.3.2 and earlier
Description
The issue allows unauthenticated users to upload malicious HTML files containing JavaScript via the plugin's form. These malicious files can be triggered when accessed directly, potentially leading to security issues.
Recommendations
For versions 1.3.2 and earlier, update to a version that prevents HTML file uploads via the plugin's form to mitigate the risk. As a temporary workaround, consider restricting access to the file upload feature until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontend Uploader