VYPR

Wp Attachments

by Marco Milesi

CVEs (3)

  • CVE-2022-4330MedJan 16, 2023
    risk 0.31cvss 4.8epss 0.00

    The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2022-3469MedNov 14, 2022
    risk 0.31cvss 4.8epss 0.01

    The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in…

  • CVE-2023-45651MedOct 16, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This issue affects WP Attachments: from n/a through 5.0.11.