Vulnerability Description
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codedropz | Drag And Drop Multiple File Upload - Contact Form 7 | < 1.3.6.3 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2686614PatchThird Party Advisory
- https://wpscan.com/vulnerability/1b849957-eaca-47ea-8f84-23a3a98cc8deExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2686614PatchThird Party Advisory
- https://wpscan.com/vulnerability/1b849957-eaca-47ea-8f84-23a3a98cc8deExploitThird Party Advisory
FAQ
What is CVE-2022-0595?
CVE-2022-0595 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Script...
How severe is CVE-2022-0595?
CVE-2022-0595 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0595?
Check the references section above for vendor advisories and patch information. Affected products include: Codedropz Drag And Drop Multiple File Upload - Contact Form 7.