CVE Published: 29/07/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: User Profile Builder Status : PUBLISHED
CVE-2024-6366 Description
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.