CVE-2021-24563
MEDIUMFrontend Uploader < 1.3.2 - XSS
Title source: ruleDescription
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Exploits (2)
Scores
CVSS v3
6.1
EPSS
0.4059
EPSS Percentile
97.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
frontend_uploader_project/frontend_uploader
< 1.3.2
Published
Oct 11, 2021
Tracked Since
Feb 18, 2026