CVE-2022-3912: User Registration < 2.2.4.1 - Subscriber+ Arbitrary File Upload
Published Dec 12, 2022
·Updated
The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.
Affected Software
1 affected component
WPEverest User Registration Wordpress<2.2.4.1
Event History
Dec 12, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-3912.
2
What is the severity of CVE-2022-3912?
The severity of CVE-2022-3912 is high with a CVSS score of 7.5.
3
What is the affected software?
The affected software is the User Registration WordPress plugin before version 2.2.4.1.
4
What is the risk of CVE-2022-3912?
CVE-2022-3912 poses a risk of unauthenticated users being able to upload malicious PHP files.
5
How can I mitigate CVE-2022-3912?
To mitigate CVE-2022-3912, update the User Registration WordPress plugin to version 2.2.4.1 or later.