PT-2024-16360 · WordPress · Wp Membership

Tonn

·

Published

2024-11-09

·

Updated

2024-11-14

·

CVE-2024-10547

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Membership plugin for WordPress versions up to, and including, 1.6.2
Description The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user profile image upload() function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server, which may make remote code execution possible.
Recommendations For WP Membership plugin for WordPress versions up to, and including, 1.6.2: Update to the latest version to secure your site. As a temporary workaround, consider disabling the user profile image upload() function until a patch is available.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-10547

Affected Products

Wp Membership