Vulnerability Details CVE-2021-24563
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Exploit prediction scoring system (EPSS) score
EPSS Score 0.3
EPSS Ranking 96.5%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-24563
-
cpe:2.3:a:frontend_uploader_project:frontend_uploader:-
-
cpe:2.3:a:frontend_uploader_project:frontend_uploader:0.9.2
-
cpe:2.3:a:frontend_uploader_project:frontend_uploader:1.3.2