CVE-2023-4536
My Account Page Editor < 1.3.2 - Subscriber+ Arbitrary File Upload
The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · My Account Page EditorWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →