
Cloud Vulnerability DB
A community-led vulnerabilities database
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress contains a Stored Cross-Site Scripting vulnerability (CVE-2024-2324) discovered in versions up to and including 1.0.6. The vulnerability was disclosed on May 2, 2024, affecting the file upload functionality of the plugin (NVD).
The vulnerability stems from insufficient input sanitization and output escaping specifically related to SVG file uploads. The CVSS v3.1 score is 4.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N, indicating a network-accessible vulnerability requiring high privileges and high attack complexity (Wordfence).
When successfully exploited, the vulnerability allows authenticated attackers to inject arbitrary web scripts that execute when users access the affected pages. For the free version, the impact is limited to administrators, while the pro version can potentially affect lower-level users down to subscriber level if the functionality is enabled (NVD).
The vulnerability requires authentication to exploit. In the free version, only administrators can exploit the vulnerability. However, in the pro version, the exploit potential extends to lower-privileged users if the functionality is enabled for those roles (NVD).
Users should update to a version newer than 1.0.6 of the FileOrganizer plugin. For those unable to update immediately, it's recommended to restrict access to the file upload functionality to only trusted administrators (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."