CVE-2021-24563

MEDIUM

Frontend Uploader < 1.3.2 - XSS

Title source: rule

Description

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

Exploits (2)

exploitdb WORKING POC
by Veshraj Ghimire · textwebappsphp
https://www.exploit-db.com/exploits/50655
nomisec WORKING POC 1 stars
by V35HR4J · poc
https://github.com/V35HR4J/CVE-2021-24563

Scores

CVSS v3 6.1
EPSS 0.4059
EPSS Percentile 97.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
frontend_uploader_project/frontend_uploader < 1.3.2
Published Oct 11, 2021
Tracked Since Feb 18, 2026