Sploitus

CVE-2024-6366

1 known exploit for CVE-2024-6366

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

Affected products
User Profile Builder
Cozmoslabs Profile Builder
< 3.11.8
Fix
Available
CVSS 3.1
9.1 CRITICAL
EPSS
29.0% (98th percentile)
Weakness
CWE-434
NVD status
Analyzed
Published
2024-07-29
CVE-2024-6366 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-6366

Proof-of-concept code and exploit modules indexed by Sploitus