Lucene search

K
cvelistWPScanCVELIST:CVE-2023-4821
HistoryOct 16, 2023 - 7:39 p.m.

CVE-2023-4821 Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting

2023-10-1619:39:23
WPScan
www.cve.org
6
cve-2023-4821
woocommerce
wordpress
unfiltered file extensions
cross-site scripting

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

20.8%

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Drag and Drop Multiple File Upload for WooCommerce",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "1.1.1"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

20.8%

Related for CVELIST:CVE-2023-4821