Vulnerability Description
The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Upload Resume Project | Upload Resume | <= 1.2.0 |
References
- https://wpscan.com/vulnerability/1b0fe0ac-d0d1-473d-af5b-dad6217933d4ExploitThird Party Advisory
- https://wpscan.com/vulnerability/1b0fe0ac-d0d1-473d-af5b-dad6217933d4ExploitThird Party Advisory
FAQ
What is CVE-2023-2751?
CVE-2023-2751 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbit...
How severe is CVE-2023-2751?
CVE-2023-2751 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2751?
Check the references section above for vendor advisories and patch information. Affected products include: Upload Resume Project Upload Resume.