NA

CVE-2023-4536

Published: 16/01/2024 Updated: 23/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The My Account Page Editor WordPress plugin prior to 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

Vulnerable Product Search on Vulmon Subscribe to Product

koalaapps my account page editor