PT-2024-16483 · Yandex · Yadisk Files Wordpress Plugin

Bob Matyas

·

Published

2024-11-25

·

Updated

2026-01-09

·

CVE-2024-10710

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions YaDisk Files WordPress plugin versions 1.2.5 and earlier
Description The YaDisk Files WordPress plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered html capability is disallowed, for example in multisite setup.
Recommendations For YaDisk Files WordPress plugin versions 1.2.5 and earlier, update to the latest version to mitigate risks. As a temporary workaround, consider restricting access to the plugin's settings to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-10710

Affected Products

Yadisk Files Wordpress Plugin