CVE-2022-3912

Severity
7.5HIGH
EPSS
0.5%
top 34.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5unknown/user_registration< 2.2.4.1

🔴Vulnerability Details

2
GHSA
GHSA-r7xp-c243-63mm: The User Registration WordPress plugin before 22022-12-12
CVEList
User Registration < 2.2.4.1 - Subscriber+ Arbitrary File Upload2022-12-12
CVE-2022-3912 (HIGH CVSS 7.5) | The User Registration WordPress plu | cvebase.io