CVE-2023-4536

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:koalaapps:my_account_page_editor:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-01-16 16:15

Updated : 2024-01-23 19:38


NVD link : CVE-2023-4536

Mitre link : CVE-2023-4536

CVE.ORG link : CVE-2023-4536


JSON object : View

Products Affected

koalaapps

  • my_account_page_editor
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type