Sceawere
Vulnerability Detail
CVE-2026-3717UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Arbitrary File Upload Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- bestwpdeveloper
- Product
- WP CV Builder
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-10T07:16:41.507Z",
"pubdate": "2026-10-10T07:16:41.507Z",
"executiveSummary": "The CV Builder – Professional Resume Builder SaaS plugin for WordPress, in all versions up to and including 1.3.1, contains a critical security vulnerability involving an improper access control mechanism.\nSpecifically, the 'wp_save_signature_image' function lacks the necessary capability checks required to restrict access to authenticated users.\nThis flaw enables an unauthenticated attacker to execute an arbitrary file upload attack, allowing the remote injection of malicious content into the WordPress uploads directory.\nThe successful exploitation of this vulnerability poses a severe risk to the confidentiality, integrity, and availability of the affected WordPress site.\nBy bypassing authorization constraints, an attacker can upload arbitrary files, typically masked as .png images, which may subsequently be leveraged to achieve Remote Code Execution (RCE) if the web server is improperly configured to process uploaded files or if the attacker successfully tricks the server into executing the uploaded payload.\nThe vulnerability is accessible to unauthenticated remote attackers without requiring prior interaction or privileged credentials, representing a significant threat vector.",
"technicalDetails": "The root cause of this vulnerability lies in the implementation of the 'wp_save_signature_image' function within the CV Builder – Professional Resume Builder SaaS plugin. The function fails to implement a proper security check—such as current_user_can()—to verify that the requesting user possesses the appropriate permissions to perform file upload operations.\nIn the context of the WordPress security model, functions that handle sensitive operations like file uploads must validate the user's authorization before processing incoming data. Because 'wp_save_signature_image' lacks this essential check, it is publicly exposed as a reachable endpoint for any request directed at the site, regardless of the sender's identity.\nThe attack flow proceeds as follows: An attacker identifies the accessible function via the plugin's REST API or admin-ajax hooks. The attacker crafts a malicious payload, typically disguised or embedded within a file that the application accepts under the assumption that it is a signature image. The attacker then transmits a multipart/form-data request to the server, targeting the vulnerable endpoint.\nSince the backend performs no verification of the user's role or the authenticity of the request, the function proceeds to handle the file upload. The file is saved directly into the WordPress uploads directory. While the vulnerability description notes that files are uploaded as .png files, the lack of server-side content validation or file type enforcement allows for the potential upload of malicious scripts or shells.\nPost-exploitation impact is high. Once an attacker has successfully placed a file on the server, they may attempt to gain Remote Code Execution. If the server environment is configured to allow the execution of scripts within the uploads directory, the attacker can execute arbitrary code by navigating to the direct URL of the uploaded file. This could lead to a full site takeover, unauthorized database access, or the deployment of web shells for persistent unauthorized access to the underlying server environment. The attack is fully remote, requires no authentication, and can be automated, making it a critical risk for all deployments running versions 1.3.1 and below."
}