Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 26%
from disclosure to weapon0 days
Published on NVDOct 11
1st PoCOct 5
exploitation probability
26%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
Affected products
Unknown · Frontend Uploaderpublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/50655unverifiedgithubgithub.com/V35HR4J/CVE-2021-24563★ 1cve_referencepacketstormsecurity.com/files/165515/WordPress-Frontend-Uploader-1.3.2-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.