The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/7f9271f2-4de4-4be3-8746-2a3f149eb1d1 | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/7f9271f2-4de4-4be3-8746-2a3f149eb1d1 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-10-16 20:15
Updated : 2025-04-23 17:16
NVD link : CVE-2023-4811
Mitre link : CVE-2023-4811
CVE.ORG link : CVE-2023-4811
JSON object : View
Products Affected
iptanus
- wordpress_file_upload
CWE
No CWE.