CVE-2023-4811
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-4811 is a vulnerability affecting the WordPress File Upload plugin before version 4.23.3. This issue permits contributors, who have high privileges, to execute Stored Cross-Site Scripting (XSS) attacks. The plugin fails to properly sanitize and escape certain settings, allowing malicious scripts to be injected and executed in the context of the affected website. The vulnerability poses a significant risk to websites using the plugin and could potentially lead to unauthorized access, data theft, or website defacement. It is recommended that users update the plugin to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.