RSS   Vulnerabilities for 'Wp-upload-restriction'   RSS

2021-07-07
 
CVE-2021-34625

CWE-79
 

 
A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior.

 
 
CVE-2021-34626

CWE-863
 

 
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

 
 
CVE-2021-34627

CWE-863
 

 
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

 


Copyright 2024, cxsecurity.com

 

Back to Top