Use-your-Drive | Google Drive plugin for WordPress <= 3.3.1- Unauthenticated Stored Cross-Site Scripting via File Metadata
high
The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbit...
- CVSS:
- 7.2
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Aug 4, 2025
CVE-2025-7050 on NVD →
Use-Your-Drive [use-your-drive] < 1.18.3
unknown
[en] Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
- Affected:
- up to 1.18.3
- Fixed in:
- 1.18.3
- Disclosed:
- Dec 13, 2021
CVE-2021-42546 on NVD →
Use-Your-Drive < 1.18.3 - Reflected Cross-Site Scripting
medium
Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
- CVSS:
- 6.1
- Affected:
- up to 1.18.3
- Fixed in:
- 1.18.3
- Disclosed:
- Dec 6, 2021
CVE-2021-42546 on NVD →
Use-Your-Drive [use-your-drive] < 3.3.2
unknown
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
CVE-2025-7050 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database