CVE-2021-24960

MEDIUM

WordPress File Upload <4.16.3 - XSS

Title source: llm
STIX 2.1

Description

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/18902832-2973-498d-808e-c75d1aedc11e
Patch, Third Party Advisory x_refsource_confirm
https://plugins.trac.wordpress.org/changeset/2677722

Scores

CVSS v3 5.4
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-434
Status published
Products (2)
iptanus/wordpress_file_upload < 4.16.3
iptanus/wordpress_file_upload_pro < 4.16.3
Published Mar 07, 2022
Tracked Since Feb 18, 2026