WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss, ccd9b56c6ffe2d1ea77cee81dcd3d453c7ce6839
- CVE, Research URL
- Published on
- Feb 08, 2016
- Research Description
- User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration [wp-user-frontend] < 2.3.11 WP User Frontend < 2.3.11 - Arbitrary File Upload The WP User Frontend plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpuf_file_upload' and 'wpuf_insert_image' AJAX actions in versions before 2.3.11. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected versions
-
max 2.3.11.
- Status
-
vulnerable