Description
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.1.4 or higher.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 15 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:properfraction:profilepress:-:*:*:*:*:wordpress:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-10-15T18:51:23.584Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34624
Updated: 2024-08-04T00:19:47.669Z
Status : Modified
Published: 2021-07-07T13:15:08.713
Modified: 2024-11-21T06:10:50.177
Link: CVE-2021-34624
No data.
OpenCVE Enrichment
No data.
Weaknesses