First published: Mon Mar 07 2022(Updated: )
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Iptanus WordPress File Upload | <4.16.3 | |
Iptanus WordPress File Upload | <4.16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24961 is a vulnerability in the WordPress File Upload WordPress plugin before version 4.16.3 and wordpress-file-upload-pro plugin before version 4.16.3, which allows users with a role as low as Contributor to perform Cross-Site Scripting attacks.
CVE-2021-24961 has a severity rating of 5.4 (medium).
The WordPress File Upload WordPress plugin before version 4.16.3 and wordpress-file-upload-pro plugin before version 4.16.3 are affected by CVE-2021-24961.
To fix CVE-2021-24961, update the WordPress File Upload WordPress plugin and the wordpress-file-upload-pro plugin to version 4.16.3 or later.
More information about CVE-2021-24961 can be found at the following references: [https://plugins.trac.wordpress.org/changeset/2677722](https://plugins.trac.wordpress.org/changeset/2677722) and [https://wpscan.com/vulnerability/c911bbbd-0196-4e3d-ada3-4efb8a339954](https://wpscan.com/vulnerability/c911bbbd-0196-4e3d-ada3-4efb8a339954).