CVE-2024-1169
07.03.2024, 11:15
The Post Form Registration Form Profile Form for User Profiles Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media upload due to a missing capability check on the buddyforms_upload_handle_dropped_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to upload media files.Enginsight
Vendor | Product | Version |
---|---|---|
themekraft | post_form | 𝑥 < 2.8.8 |
𝑥
= Vulnerable software versions
References