PoC Index

CVE-2024-6366

CRITICAL 9.1EPSS 29.0%

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
28.99% chance of exploitation in the next 30 days, 98th percentile
Nuclei
high
Published
2024-07-29
Updated
2024-08-01

Proof-of-concept exploits (3)

Nuclei templates (1)

References

Related