PT-2024-37570 · WordPress · User Profile Builder

Michel Prunet

·

Published

2024-07-29

·

Updated

2025-02-02

·

CVE-2024-6366

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions User Profile Builder WordPress plugin versions prior to 3.11.8
Description The issue allows unauthenticated users to upload media files via the async upload functionality of WordPress due to a lack of proper authorization.
Recommendations For versions prior to 3.11.8, update to version 3.11.8 or later to resolve the issue. As a temporary workaround, consider disabling the async upload functionality until a patch is available. Restrict access to the media upload feature to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-6366

Affected Products

User Profile Builder