Security Advisory

CVE-2024-6366

9.1
CRITICAL

Vulnerability Description

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
Published Date July 29, 2024
Official Source NIST NVD Advisory