CVE-2024-1169: Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media upload due to a missing capability check on the buddyformsuploadhandledroppedmedia function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to upload media files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1169?
CVE-2024-1169 has a medium severity rating due to the potential for unauthorized media uploads.
How do I fix CVE-2024-1169?
To fix CVE-2024-1169, update the WordPress Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin to version 2.8.8 or later.
What does CVE-2024-1169 affect?
CVE-2024-1169 affects all versions of the WordPress Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin up to version 2.8.7.
What type of vulnerability is CVE-2024-1169?
CVE-2024-1169 is a vulnerability that allows unauthorized media uploads due to a missing capability check.
Who is affected by CVE-2024-1169?
Anyone using versions up to 2.8.7 of the WordPress Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin is affected by CVE-2024-1169.