Unrated severityNVD Advisory· Published Aug 6, 2024· Updated Aug 6, 2024
WordPress File Upload < 4.24.8 - Reflected XSS
CVE-2024-6651
Description
The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected products
2- Range: <4.24.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/65e2c77d-09bd-4a44-81d9-d7a5db0e0f84/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.