VYPR
Unrated severityNVD Advisory· Published Mar 7, 2022· Updated Aug 3, 2024

WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Shortcode

CVE-2021-24961

Description

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.