CVE

CVE-2018-20149

CVE-2018-20149

In WordPress versions before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS.

Source: CVE-2018-20149

Exit mobile version