Sploitus

CVE-2021-24960

1 known exploit for CVE-2021-24960

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

Iptanus Wordpress File Upload
< 4.16.3
Iptanus Wordpress File Upload Pro
< 4.16.3
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.8% (53th percentile)
Weakness
CWE-434
NVD status
Modified
Published
2022-03-07
CVE-2021-24960 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24960

Proof-of-concept code and exploit modules indexed by Sploitus