CVE-2017-9061

MEDIUM

WordPress <4.7.5 - XSS

Title source: llm

Description

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

Scores

CVSS v3 6.1
EPSS 0.0331
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
n/a/n/a
wordpress/wordpress < 4.7.4
debian/debian_linux
debian/debian_linux
Published May 18, 2017
Tracked Since Feb 18, 2026