CVE-2024-6366
9.1
CRITICAL · CVSS 3.1 · EPSS 29% (pctl 98)
Patch early
EPSS 29% — above the 10% action threshold.
Description
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 28.99% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2024-07-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| cozmoslabs | profile builder |
References
→ the Explorer · watch your stack · NVD