Lucene search

K
cvelistWPScanCVELIST:CVE-2023-4536
HistoryJan 16, 2024 - 3:56 p.m.

CVE-2023-4536 My Account Page Editor < 1.3.2 - Subscriber+ Arbitrary File Upload

2024-01-1615:56:33
WPScan
www.cve.org
5
wordpress
plugin
vulnerability
arbitrary file upload
rce

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

19.3%

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "My Account Page Editor",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "1.3.2"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

19.3%

Related for CVELIST:CVE-2023-4536