Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3912


The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.


Published

2022-12-12T18:15:11.753

Last Modified

2025-04-22T16:15:35.560

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wpeverest user_registration < 2.2.4.1 Yes

References