CVE-2022-3832
Published Dec 19, 2022The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-S…
Vendor/product archive
2 CVEs tagged to external_media_project / external_media — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-S…
The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.