Critical 9.8
2025-08-16< 1.0.43
WordPress StoryChief Plugin <= 1.0.42 is vulnerable to Arbitrary File Upload
Minimum safe version
1.0.43
Update to 1.0.43 or later to address 6 fixable vulnerabilities
WordPress StoryChief Plugin <= 1.0.42 is vulnerable to Arbitrary File Upload
StoryChief < 1.0.31 - Reflected Cross-Site Scripting (XSS)
StoryChief < 1.0.31 - Authenticated Stored Cross-Site Scripting (XSS)
StoryChief <= 1.0.30 - Authenticated Stored Cross-Site Scripting
StoryChief <= 1.0.30 - Reflected Cross-Site Scripting
WordPress StoryChief plugin <= 1.0.30 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability