Medium 6.5
2025-02-16< 3.0.4
CVE-2025-22676
Minimum safe version
3.0.4
Update to 3.0.4 or later to address 4 fixable vulnerabilities
CVE-2025-22676
WordPress AWS S3 for WordPress Plugin – Upcasted Plugin <= 3.0.2 is vulnerable to Cross Site Scripting (XSS)
WordPress AWS S3 for WordPress Plugin – Upcasted plugin <= 3.0.0 - Sensitive Information Disclosure vulnerability
WordPress AWS S3 for WordPress Plugin – Upcasted plugin <= 3.0.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability