Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
9.1CRITICAL
EPSS
91.5%
top 0.33%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 29

Description

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-wrpc-6v65-cc7f: The User Profile Builder WordPress plugin before 32024-07-29
CVEList
User Profile Builder < 3.11.8 - Unauthenticated Media Upload2024-07-29

💥Exploits & PoCs

1
Nuclei
User Profile Builder < 3.11.8 - File Upload
CVE-2024-6366 (CRITICAL CVSS 9.1) | The User Profile Builder WordPress | cvebase.io