
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical vulnerability was discovered in the ProfilePress WordPress plugin (formerly wp-user-avatar) affecting versions 3.0.0 through 3.1.3. The vulnerability, identified as CVE-2021-34623, was found in the image uploader component specifically in the ~/src/Classes/ImageUploader.php file, which allowed users to upload arbitrary files during user registration or profile updates (Wordfence Blog, CVE Details).
The vulnerability stems from improper file type validation in the cover photo and profile photo upload functionalities. The plugin used exif_imagetype for filetype checking, which proved insufficient for security purposes. The vulnerability received a Critical CVSS Score of 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (Wordfence Blog).
The vulnerability could allow attackers to upload arbitrary files to the affected WordPress installations, potentially leading to complete site compromise. Given the critical CVSS score of 9.8, the impact of successful exploitation would be severe, affecting the confidentiality, integrity, and availability of the system (Wordfence Blog).
The vulnerability was considered easily exploitable, requiring no authentication or special user interaction. The issue could be triggered during user registration or profile update processes, making it particularly dangerous (WPScan).
The vulnerability was patched in ProfilePress version 3.1.4. Site administrators running affected versions were strongly advised to update to this version immediately to mitigate the risk (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."