CVE-2023-4821: Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4821?
CVE-2023-4821 is a vulnerability in the Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before version 1.1.1.
How severe is CVE-2023-4821?
CVE-2023-4821 is considered to have a severity rating of medium, with a CVSS score of 5.4.
What is the impact of CVE-2023-4821?
CVE-2023-4821 allows an attacker to upload unsafe .shtml or .svg files containing malicious scripts, potentially leading to remote code execution or other types of attacks.
How can I fix CVE-2023-4821?
To fix CVE-2023-4821, update the Drag and Drop Multiple File Upload for WooCommerce WordPress plugin to version 1.1.1 or later, which includes a fix for this vulnerability.
Where can I find more information about CVE-2023-4821?
You can find more information about CVE-2023-4821 at the following reference link: [https://wpscan.com/vulnerability/3ac0853b-03f7-44b9-aa9b-72df3e01a9b5](https://wpscan.com/vulnerability/3ac0853b-03f7-44b9-aa9b-72df3e01a9b5)