VulnerabilityModified
CVE-2023-4821
Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.
MEDIUM 5.4EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- codedropz/drag and drop multiple file uploader
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/3ac0853b-03f7-44b9-aa9b-72df3e01a9b5Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/3ac0853b-03f7-44b9-aa9b-72df3e01a9b5Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.