The plugin does not validate and sanitise task’s attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
Create a SVG with the following content: As any authenticated user, such as subscriber: - Go to http://vuln.local/wp-admin/admin.php?page=wppm-tasks - Choose any tasks (create one if there aren’t any) - Focus on “Write a comment”. - Click on “Attach Files” and select the SVG created above - Click on “Send”. - View the attached SVG by clicking on its URL (https://example.com/?wppm_attachment=86&tid;=1&tac;=OtjI9JpnQU), which will trigger the XSS