The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published: 2021-10-11T10:45:30
Updated: 2024-08-03T19:35:20.198Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24563

No data.

Status : Modified
Published: 2021-10-11T11:15:08.747
Modified: 2024-11-21T05:53:18.673
Link: CVE-2021-24563

No data.