PT-2023-30734 · WordPress · Drag/Drop Multiple File Upload

Zeyad Alshahrani

·

Published

2023-10-16

·

Updated

2023-10-20

·

CVE-2023-4821

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drag and Drop Multiple File Upload for WooCommerce WordPress plugin versions prior to 1.1.1
Description The issue allows an attacker to upload unsafe files, including .shtml or .svg files, which can contain malicious scripts. This is due to the plugin not filtering all potentially dangerous file extensions.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to only trusted users or disabling the file upload feature until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-4821

Affected Products

Drag/Drop Multiple File Upload