WordPress Rocket Media Library Mime Type Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Rocket Media Library Mime Type plugin, affecting versions through 2.1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.
Impact
Exploitation of this vulnerability could enable Stored Cross-Site Scripting, where injected scripts are executed in the context of the user.
Remediation
Users of the WordPress Rocket Media Library Mime Type plugin are advised to update to a version later than 2.1.0. For those unable to update immediately, Patchstack offers a virtual patch that can be applied to mitigate this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
