First published: Mon Jun 19 2023(Updated: )
The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpfactory File Renaming On Upload | <2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the File Renaming on Upload WordPress plugin is CVE-2023-2684.
The severity of CVE-2023-2684 is medium with a severity value of 4.8.
The File Renaming on Upload WordPress plugin before version 2.5.2 is affected by CVE-2023-2684.
CVE-2023-2684 allows high privilege users, such as admin, to perform Stored Cross-Site Scripting attacks.
To fix the CVE-2023-2684 vulnerability, you should update the File Renaming on Upload WordPress plugin to version 2.5.2 or later.