WordPress Plugin Vulnerabilities

Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting

Description

The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

Proof of Concept

Affects Plugins

No known fix

References

YouTube Video

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Veshraj Ghimire
Submitter
Vess Razz
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-09-21 (about 4 years ago)
Added
2021-09-21 (about 4 years ago)
Last Updated
2022-04-09 (about 3 years ago)

Other