Vulnerabilities > Kaswara Project > Kaswara > 3.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-05-14 CVE-2021-24284 Unrestricted Upload of File with Dangerous Type vulnerability in Kaswara Project Kaswara 3.0.1
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action.
network
low complexity
kaswara-project CWE-434
critical
9.8