CVE-2022-0595: Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dndcodedropzupload AJAX action, which could lead to Stored Cross-Site Scripting issue
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0595?
CVE-2022-0595 is a vulnerability in the Drag and Drop Multiple File Upload WordPress plugin that allows SVG files to be uploaded, leading to a Stored Cross-Site Scripting issue.
What is the severity of CVE-2022-0595?
CVE-2022-0595 has a severity of medium with a CVSS score of 5.4.
How does CVE-2022-0595 affect Codedropz Drag And Drop Multiple File Upload - Contact Form 7 plugin?
CVE-2022-0595 affects Codedropz Drag And Drop Multiple File Upload - Contact Form 7 plugin versions up to 1.3.6.3.
How can the vulnerability in CVE-2022-0595 be exploited?
The vulnerability in CVE-2022-0595 can be exploited by uploading SVG files via the dnd_codedropz_upload AJAX action, leading to potential Stored Cross-Site Scripting attacks.
What is the Common Weakness Enumeration (CWE) for CVE-2022-0595?
The Common Weakness Enumeration (CWE) for CVE-2022-0595 is CWE-79, which is a category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').