WP Upload Restriction Project maintains a narrowly focused WordPress plugin designed to control file-upload permissions and access, a common requirement in multi-user and managed WordPress deployments. The identified vulnerability surface is limited and centers on the plugin's upload-handling mechanism. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Upload Restriction Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34625MEDIUM A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affect | Jul 7, 2021 | 5.4 | 18 | NO | NO |
CVE-2021-34627MEDIUM A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by adm | Jul 7, 2021 | 4.3 | 17 | NO | NO |
CVE-2021-34626MEDIUM A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrat | Jul 7, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Upload Restriction Project.
Media articles that mention a CVE ID that affects a product developed by Wp Upload Restriction Project — matched by CVE ID, not by vendor name.