cleantalk
Vulnerabilities and Security Researches

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, CVE-2024-6366

CVE, Research URL

CVE-2024-6366

Published on
Jul 29, 2024
Research Description
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
Affected versions
Min -, max 3.11.8.
Status
vulnerable