CVE-2024-6366
EUVD-2024-4747329.07.2024, 06:15
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cozmoslabs | profile_builder | 𝑥 < 3.11.8 |
| cozmoslabs | profile_builder | 𝑥 < 3.11.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration