PT-2024-13240 · WordPress · My Account Page Editor

Alexander Concha

·

Published

2024-01-16

·

Updated

2024-01-23

·

CVE-2023-4536

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions My Account Page Editor WordPress plugin versions prior to 1.3.2
Description The issue allows any authenticated users to upload arbitrary files to the server, leading to remote code execution (RCE). This is due to the lack of validation for the profile picture to be uploaded.
Recommendations For versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities for authenticated users, especially subscribers, until the update is applied.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-4536

Affected Products

My Account Page Editor