WordPress File Upload Vulnerability Leads to Reflected Cross-Site Scripting
CVE-2024-6651
Currently unrated 🤨
Summary
The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Version(s)
WordPress File Upload < 4.24.8
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Đức Tài
WPScan