plugin

Wp Extra File Types Vulnerabilities

1 known security issue reported for the Wp Extra File Types WordPress plugin. Most recent disclosed Dec 27, 2021.

1 high

Running Wp Extra File Types on your site? Check whether your installed version is affected.

Scan your site free

WP Extra File Types <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

CVSS:
8.8
Affected:
up to 0.5
Fixed in:
0.5.1
Disclosed:
Dec 27, 2021

CVE-2021-24936 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database