Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3AE2EA62-6FC0-438D-BE26-1822F5670D47
HistoryAug 11, 2022 - 12:00 a.m.

Uploading SVG, WEBP and ICO files <= 1.0.1 - Author+ Stored Cross-Site Scripting

2022-08-1100:00:00
wpscan.com
10
cross-site scripting
stored
security
plugin
parameter
author
role
upload
file

0.001 Low

EPSS

Percentile

19.4%

The plugin does not sanitise and escape some parameters which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks

CPENameOperatorVersion
uploading-svgwebp-and-ico-fileseq*

0.001 Low

EPSS

Percentile

19.4%

Related for WPVDB-ID:3AE2EA62-6FC0-438D-BE26-1822F5670D47