The WP Extra File Types Project maintains a WordPress plugin focused on extending supported file upload types, a narrowly scoped offering within the broader WordPress ecosystem. Vulnerabilities affecting this plugin center on cross-site request forgery, a class reflecting the plugin's role in handling user-submitted file operations and administrative configuration. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Extra File Types Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24936HIGH The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a | Jan 24, 2022 | 8.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Extra File Types Project.
Media articles that mention a CVE ID that affects a product developed by Wp Extra File Types Project — matched by CVE ID, not by vendor name.