The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
History

Fri, 30 May 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Cozmoslabs
Cozmoslabs profile Builder
Weaknesses CWE-434
CPEs cpe:2.3:a:cozmoslabs:profile_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Cozmoslabs
Cozmoslabs profile Builder

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-29T06:00:08.248Z

Updated: 2024-08-01T21:33:05.436Z

Reserved: 2024-06-27T01:09:24.875Z

Link: CVE-2024-6366

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.436Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-29T06:15:02.790

Modified: 2025-05-30T16:55:36.323

Link: CVE-2024-6366

cve-icon Redhat

No data.