Sploitus

CVE-2024-6651

1 known exploit for CVE-2024-6651

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected products
Wordpress File Upload
Iptanus Wordpress File Upload
< 4.24.8
Fix
Available
CVSS 3.1
6.1 MEDIUM
EPSS
15.0% (96th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2024-08-06
CVE-2024-6651 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-6651

Proof-of-concept code and exploit modules indexed by Sploitus