Upload Resume <= 1.2.0 - Captcha Bypass via resume_upload_form

2023-05-24 00:00
Yakshita Sharma

Strategic Overview

Status
Unpatched
Affected PluginUpload Resume
Affected Version<= 1.2.0
CVSS5.3Medium
CVECVE-2023-2751
View all Upload Resume vulnerabilities

Vulnerability Overview

The Upload Resume plugin for WordPress is vulnerable to captcha bypass via the form rendered by the 'resume_upload_form' shortcode in versions up to, and including, 1.2.0. This allows unauthenticated attackers to perform automated uploads of arbitrary media files.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-804 (Guessable CAPTCHA) The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C