Description Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. Remediation References CVE-2024-25978 Related Vulnerabilities WordPress Plugin 10Web Social Feed for Instagram Multiple Cross-Site Scripting Vulnerabilities (1.3.0) Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-0212) WordPress Plugin Image Slider Cross-Site Request Forgery (1.1.121) MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-37302) WordPress Plugin Church Admin Cross-Site Scripting (0.856) Severity High Classification CVE-2024-25978 CWE-770 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Tags Missing Update Known Vulnerabilities