Description
The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unrestricted File Upload
Action: Update Plugin
AI Analysis

Impact

The CV Builder – Professional Resume Builder SaaS plugin for WordPress contains a missing capability check on the wp_save_signature_image function in all versions up to and including 1.3.1. This flaw permits unauthenticated attackers to upload arbitrary data as PNG files to the WordPress uploads directory. Because the vulnerability stems from a missing authorization check (CWE‑862), an attacker can create or replace files without needing to authenticate to the site.

Affected Systems

Affected systems are installations of the WP CV Builder plugin from the vendor bestwpdeveloper with versions 1..1 or earlier. The plugin is used as a WordPress SaaS to allow users to build professional resumes, and, in these versions, the upload mechanism is exposed to all visitors.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw from the public internet by sending a crafted POST request to the wp_save_signature_image endpoint; no authentication is required. If a malicious PNG containing embedded code or payloads is uploaded, the attacker may achieve persistence or further exploitation of the WordPress site, potentially compromising confidentiality, integrity, or availability.

Generated by OpenCVE AI on October 10, 2026 at 08:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CV Builder plugin to the latest version that includes the authorization check fix.
  • If an update is unavailable, configure WordPress to prevent unauthenticated requests to the wp_save_signature_image endpoint, for example by adding a rewrite rule or using a security plugin to block unauthenticated POST requests.
  • Enforce strict upload restrictions by limiting uploads to approved file types and sizes, and sanitize the content before saving.

Generated by OpenCVE AI on October 10, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files.
Title CV Builder – Professional Resume Builder SaaS <= 1.3.1 - Missing Authorization to Unauthenticated PNG File Upload
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:15.481Z

Reserved: 2026-03-07T11:30:11.944Z

Link: CVE-2026-3717

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:41.507

Modified: 2026-10-10T07:16:41.507

Link: CVE-2026-3717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses