vendor:
Frontend Uploader
by:
Veshraj Ghimire
6.1
CVSS
MEDIUM
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: Frontend Uploader
Affected Version From: 1.3.2002
Affected Version To: 1.3.2002
Patch Exists: YES
Related CWE: CVE-2021-24563
CPE: a:wordpress:frontend_uploader
Platforms Tested: Windows 10 - Chrome, WordPress 5.8.2
2022
WordPress Plugin Frontend Uploader 1.3.2 – Stored Cross Site Scripting (XSS) (Unauthenticated)
The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly.
Mitigation:
The user should ensure that the plugin is updated to the latest version and that only trusted users are allowed to upload files.