Filtered by vendor Wp-upload-restriction Project
Subscribe
Total
3 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-34627 | 1 Wp-upload-restriction Project | 1 Wp-upload-restriction | 2022-10-27 | 3.5 LOW | 4.3 MEDIUM |
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior. | |||||
CVE-2021-34626 | 1 Wp-upload-restriction Project | 1 Wp-upload-restriction | 2022-10-27 | 4.0 MEDIUM | 4.3 MEDIUM |
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior. | |||||
CVE-2021-34625 | 1 Wp-upload-restriction Project | 1 Wp-upload-restriction | 2021-07-08 | 3.5 LOW | 5.4 MEDIUM |
A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior. |