QID 731141

Date Published: 2024-02-26

QID 731141: WordPress User Registration Arbitrary File Upload Vulnerability

User Registrations drag and drop form builder lets you create custom registration forms of any kind for your WordPress site.

CVE-2023-3342: The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the ur_upload_profile_pic function in versions up to and including 3.0.2. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1. Affected Versions:
WordPress User Registration plugin versions prior to 3.0.2.1

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for User Registration Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow attackers to perform any action the logged in administrator they targeted is allowed to do on the targeted site including installing arbitrary plugins and creating new rogue Administrator users.

  • CVSS V3 rated as Critical - 9.9 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to WP User-registration version 3.0.2 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731141

    Software Advisories
    Advisory ID Software Component Link
    user-registration plugin URL Logo wordpress.org/plugins/user-registration/#developers