First published: Wed Jul 07 2021(Updated: )
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Properfraction Profilepress | >=3.0.0<=3.1.3 |
Update to version 3.1.4 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34623 is a vulnerability in the image uploader component found in the ProfilePress WordPress plugin, which allows users to upload arbitrary files during user registration or profile updates.
CVE-2021-34623 has a severity rating of 9.8 (Critical).
CVE-2021-34623 affects the ProfilePress WordPress plugin by allowing users to upload arbitrary files during user registration or profile updates.
The ProfilePress WordPress plugin versions 3.0.0 through 3.1.3 are affected by CVE-2021-34623.
To fix CVE-2021-34623, update the ProfilePress WordPress plugin to a version beyond 3.1.3.