SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-4821

Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

MEDIUM 5.4EPSS 0.40%

Does this matter?

Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.

Description

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.40% probability · 33th percentile
CISA KEV
Not listed
Affected
codedropz/drag and drop multiple file uploader
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.