Lucene search

K
cvelistWPScanCVELIST:CVE-2022-0595
HistoryMar 28, 2022 - 5:22 p.m.

CVE-2022-0595 Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS

2022-03-2817:22:57
CWE-79
WPScan
www.cve.org
1

0.001 Low

EPSS

Percentile

42.1%

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CNA Affected

[
  {
    "product": "Drag and Drop Multiple File Upload – Contact Form 7",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.3.6.3",
        "status": "affected",
        "version": "1.3.6.3",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

42.1%