Lucene search

K
nvd[email protected]NVD:CVE-2023-4821
HistoryOct 16, 2023 - 8:15 p.m.

CVE-2023-4821

2023-10-1620:15:16
web.nvd.nist.gov
4
cve
woocommerce
wordpress
file upload
security vulnerability
script injection

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

20.8%

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

Affected configurations

Nvd
Node
codedropzdrag_and_drop_multiple_file_uploaderRange<1.1.1wordpress
VendorProductVersionCPE
codedropzdrag_and_drop_multiple_file_uploader*cpe:2.3:a:codedropz:drag_and_drop_multiple_file_uploader:*:*:*:*:*:wordpress:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

20.8%