CVE-2023-4811

CVE-2023-4811: WordPress File Upload < 4.23.3 - Author+ Stored Cross-Site Scripting

Vendor Unknown
Product WordPress File Upload
Published October 16, 2023
Last update April 23, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

Key dates

02Disclosure timeline

October 16, 2023 CVE published
April 23, 2025 Record updated