CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It affects WordPress. Its EPSS score suggests a 13.6% probability of exploitation in the next 30 days.
CVE
CVE-2022-0595
Severity
MEDIUM
CVSS
5.4
EPSS
13.58%
WordPress
Original NVD Description
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
Related CVEs
Other vulnerabilities affecting the same vendor(s)