CVE-2024-6651: WordPress File Upload < 4.24.8 - Reflected XSS
Published Aug 6, 2024
·Updated
The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
WordPress File Upload<4.24.8
Event History
Aug 6, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-6651?
CVE-2024-6651 is classified as a medium-severity vulnerability due to its potential impact on high privilege users.
2
How do I fix CVE-2024-6651?
To fix CVE-2024-6651, you should update the WordPress File Upload plugin to version 4.24.8 or later.
3
What type of vulnerability is CVE-2024-6651?
CVE-2024-6651 is a Reflected Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2024-6651?
CVE-2024-6651 affects users of the WordPress File Upload plugin, particularly high privilege users such as administrators.
5
When was CVE-2024-6651 reported?
CVE-2024-6651 was reported prior to the release of the fix in version 4.24.8 of the plugin.