cleantalk
Vulnerabilities and Security Researches

User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin, CVE-2022-3912

CVE, Research URL

CVE-2022-3912

Published on
Dec 12, 2022
Research Description
The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.
Affected versions
max 2.2.4.1.
Status
vulnerable