CVE-2023-3342: User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'uruploadprofilepic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/User Registration pluginto a version that resolves this vulnerability.Fixed in 3.0.2.1 - Compensating control
Restrict access to WordPress (especially any account that has subscriber-level or above capabilities) to reduce the risk of authenticated arbitrary file uploads while remediation is pending.
Event History
Frequently Asked Questions
What is CVE-2023-3342?
CVE-2023-3342 is a vulnerability in the User Registration plugin for WordPress that allows authenticated attackers to upload arbitrary files.
How severe is CVE-2023-3342?
CVE-2023-3342 has a severity rating of 9.9, which is considered critical.
How does CVE-2023-3342 impact WordPress?
CVE-2023-3342 impacts WordPress by allowing authenticated attackers to upload arbitrary files using the User Registration plugin.
How can I mitigate the vulnerability in User Registration plugin?
To mitigate the vulnerability in the User Registration plugin, update to version 3.0.2.1 or later.
Where can I find more information about CVE-2023-3342?
You can find more information about CVE-2023-3342 at the following references: [LINK1], [LINK2], [LINK3].