CVE-2023-4811

Severity
5.4MEDIUM
EPSS
0.1%
top 70.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMar 18

Description

The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
WordPress File Upload < 4.23.3 - Author+ Stored Cross-Site Scripting2023-10-16
GHSA
GHSA-p3qx-72c8-xc9p: The WordPress File Upload WordPress plugin before 42023-10-16

💥Exploits & PoCs

1
Exploit-DB
WordPress File Upload Plugin < 4.23.3 - Stored XSS2024-03-18