vendor:
WordPress File Upload
by:
ManhNho
6.1
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: WordPress File Upload
Affected Version From: 4.3.3
Affected Version To: 4.3.3
Patch Exists: YES
Related CWE: CVE-2018-9844
CPE: a:iptanus:wordpress_file_upload
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 / Cent OS 6.5
2018
WordPress Plugin WordPress File Upload 4.3.3 – Stored XSS
WordPress File Upload is a WordPress plugin with more than 20.000 active installations. Version 4.3.3 (and possibly previous versions) are affected by a Stored XSS vulnerability in the admin panel, related to the 'Edit_Setting' functionality.
Mitigation:
Ensure that all user input is properly validated and sanitized before being used in the application.