Input validation vulnerability in User Meta – User Profile Builder and User management plugin 1.1.1

The User Meta plugin for WordPress is vulnerable to malicious files being uploaded without proper protection. This means that attackers can upload malicious files, which can then be used to gain access to the WordPress website, and execute code remotely. Versions of the plugin up to and including 1.1.1 are affected, as there is insufficient file type validation in the user-meta/framework/helper/uploader.php file.

Detected in:

User Meta – User Profile Builder and User management plugin open vulnerable versions: >= 1.1.1 <= 1.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.