Loading
The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.
Use CWE-434, Wpeverest vendor hub and User Registration product page to widen CVE-2022-3912 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-3342, CVE-2023-3343 and CVE-2025-1511 for nearby disclosures in the same product family.