The Frontend Uploader WordPress plugin up to and including 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
frontend uploader project frontend uploader |