CVE-2021-34623: ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34623?
CVE-2021-34623 is a vulnerability in the image uploader component found in the ProfilePress WordPress plugin, which allows users to upload arbitrary files during user registration or profile updates.
What is the severity of CVE-2021-34623?
CVE-2021-34623 has a severity rating of 9.8 (Critical).
How does CVE-2021-34623 affect the ProfilePress WordPress plugin?
CVE-2021-34623 affects the ProfilePress WordPress plugin by allowing users to upload arbitrary files during user registration or profile updates.
Which versions of the ProfilePress WordPress plugin are affected by CVE-2021-34623?
The ProfilePress WordPress plugin versions 3.0.0 through 3.1.3 are affected by CVE-2021-34623.
How can I fix CVE-2021-34623?
To fix CVE-2021-34623, update the ProfilePress WordPress plugin to a version beyond 3.1.3.