CVE-2023-4536

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
16/01/2024
Last modified:
20/06/2025

Description

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:koalaapps:my_account_page_editor:*:*:*:*:*:wordpress:*:* 1.3.2 (excluding)