CVE-2021-24961: WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Shortcode
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-24961?
CVE-2021-24961 is a vulnerability in the WordPress File Upload WordPress plugin before version 4.16.3 and wordpress-file-upload-pro plugin before version 4.16.3, which allows users with a role as low as Contributor to perform Cross-Site Scripting attacks.
How severe is CVE-2021-24961?
CVE-2021-24961 has a severity rating of 5.4 (medium).
Which software is affected by CVE-2021-24961?
The WordPress File Upload WordPress plugin before version 4.16.3 and wordpress-file-upload-pro plugin before version 4.16.3 are affected by CVE-2021-24961.
How do I fix CVE-2021-24961?
To fix CVE-2021-24961, update the WordPress File Upload WordPress plugin and the wordpress-file-upload-pro plugin to version 4.16.3 or later.
Where can I find more information about CVE-2021-24961?
More information about CVE-2021-24961 can be found at the following references: [https://plugins.trac.wordpress.org/changeset/2677722](https://plugins.trac.wordpress.org/changeset/2677722) and [https://wpscan.com/vulnerability/c911bbbd-0196-4e3d-ada3-4efb8a339954](https://wpscan.com/vulnerability/c911bbbd-0196-4e3d-ada3-4efb8a339954).