The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-12T17:54:35.983Z

Updated:

Reserved: 2022-11-09T14:25:36.870Z


Link: CVE-2022-3912

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-12-12T18:15:11.753

Modified: 2023-11-07T03:51:57.353


Link: CVE-2022-3912

JSON object: View

cve-icon Redhat Information

No data.

CWE