First published: Thu Jul 13 2023(Updated: )
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.
Credit: security@wordfence.com security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPEverest User Registration | <3.0.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3342 is a vulnerability in the User Registration plugin for WordPress that allows authenticated attackers to upload arbitrary files.
CVE-2023-3342 has a severity rating of 9.9, which is considered critical.
CVE-2023-3342 impacts WordPress by allowing authenticated attackers to upload arbitrary files using the User Registration plugin.
To mitigate the vulnerability in the User Registration plugin, update to version 3.0.2.1 or later.
You can find more information about CVE-2023-3342 at the following references: [LINK1], [LINK2], [LINK3].