Vulnerabilities (CVE)

Filtered by vendor Wp-upload-restriction Project Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34627 1 Wp-upload-restriction Project 1 Wp-upload-restriction 2024-11-21 3.5 LOW 4.3 MEDIUM
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
CVE-2021-34626 1 Wp-upload-restriction Project 1 Wp-upload-restriction 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
CVE-2021-34625 1 Wp-upload-restriction Project 1 Wp-upload-restriction 2024-11-21 3.5 LOW 6.4 MEDIUM
A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior.