Description
The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.
Published: 2021-04-12
Score: 9.8 Critical
EPSS: 5.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-11136 The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.
History

No history.

Subscriptions

Williamluis Wp-curriculo Vitae Free
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:21:18.724Z

Reserved: 2021-01-14T00:00:00.000Z

Link: CVE-2021-24222

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-12T14:15:15.633

Modified: 2024-11-21T05:52:37.700

Link: CVE-2021-24222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses