CVE-2023-4811: WordPress File Upload < 4.23.3 - Author+ Stored Cross-Site Scripting
Published Oct 16, 2023
·Updated
The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Iptanus Wordpress File Upload Wordpress<4.23.3
Event History
Oct 16, 2023
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this WordPress File Upload plugin vulnerability?
The vulnerability ID for this WordPress File Upload plugin vulnerability is CVE-2023-4811.
2
What is the severity of CVE-2023-4811?
The severity of CVE-2023-4811 is medium.
3
What is the affected software for CVE-2023-4811?
The affected software for CVE-2023-4811 is the WordPress File Upload plugin before version 4.23.3.
4
What is the CWE ID for CVE-2023-4811?
The CWE ID for CVE-2023-4811 is CWE-79.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by high privilege users, such as contributors, to perform Stored Cross-Site Scripting (XSS) attacks.