Логотип exploitDog
bind:CVE-2023-4536
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4536

Количество 2

Количество 2

nvd логотип

CVE-2023-4536

около 2 лет назад

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-5qx2-wfg4-53mm

около 2 лет назад

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-4536

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-5qx2-wfg4-53mm

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CVSS3: 8.8
1%
Низкий
около 2 лет назад

Уязвимостей на страницу