CVE-2023-4536

Publication date

2024-01-16 15:56:33

Family

WPScan

State

PUBLISHED

Description

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE