The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:56:33.488Z

Updated: 2024-08-02T07:31:06.284Z

Reserved: 2023-08-25T08:23:02.486Z

Link: CVE-2023-4536

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-16T16:15:13.220

Modified: 2024-01-23T19:38:31.160

Link: CVE-2023-4536

cve-icon Redhat

No data.