Loading...
Loading...
The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.
September 12, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-5738
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.