PT-2022-24743 · WordPress · User Registration
Cydave
·
Published
2022-12-12
·
Updated
2022-12-14
·
CVE-2022-3912
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
User Registration WordPress plugin versions prior to 2.2.4.1
Description
The issue concerns the improper restriction of file uploads via an AJAX action, which is accessible to both unauthenticated and authenticated users. This could allow unauthenticated users to upload PHP files, for example.
Recommendations
For versions prior to 2.2.4.1, update to version 2.2.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action used for file uploads to prevent unauthenticated users from uploading malicious files.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Registration