CVE-2021-34623
WordPress vulnerability analysis and mitigation

Overview

A critical vulnerability was discovered in the ProfilePress WordPress plugin (formerly wp-user-avatar) affecting versions 3.0.0 through 3.1.3. The vulnerability, identified as CVE-2021-34623, was found in the image uploader component specifically in the ~/src/Classes/ImageUploader.php file, which allowed users to upload arbitrary files during user registration or profile updates (Wordfence Blog, CVE Details).

Technical details

The vulnerability stems from improper file type validation in the cover photo and profile photo upload functionalities. The plugin used exif_imagetype for filetype checking, which proved insufficient for security purposes. The vulnerability received a Critical CVSS Score of 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (Wordfence Blog).

Impact

The vulnerability could allow attackers to upload arbitrary files to the affected WordPress installations, potentially leading to complete site compromise. Given the critical CVSS score of 9.8, the impact of successful exploitation would be severe, affecting the confidentiality, integrity, and availability of the system (Wordfence Blog).

Exploitability

The vulnerability was considered easily exploitable, requiring no authentication or special user interaction. The issue could be triggered during user registration or profile update processes, making it particularly dangerous (WPScan).

Mitigation and workarounds

The vulnerability was patched in ProfilePress version 3.1.4. Site administrators running affected versions were strongly advised to update to this version immediately to mitigate the risk (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16974MEDIUM6.4
  • kirki
NoYesAug 11, 2026
CVE-2026-14549NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-14548NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management