CyberRota Analysis
AI-GeneratedThe Verge3D Publishing and E-Commerce WordPress plugin prior to version 4.13.1 is vulnerable due to inadequate validation of uploaded files, enabling unauthenticated attackers to upload malicious JavaScript files. This vulnerability can lead to cross-site scripting (XSS) attacks, affecting any user who accesses the compromised files in their browser. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.