CVE-2024-6366
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
- Published
- Jul 29, 2024
- Updated
- Aug 1, 2024
- Assigning CNA
- WPScan
- Evidence observed
- Aug 7, 2026
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NModerate · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8, uploading and executing a PHP payload.
User Profile Builder <= 3.11.7 - Unauthenticated Media Upload
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.