The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files. | |
| Title | CV Builder – Professional Resume Builder SaaS <= 1.3.1 - Missing Authorization to Unauthenticated PNG File Upload | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-10T06:40:15.481Z
Reserved: 2026-03-07T11:30:11.944Z
Link: CVE-2026-3717
No data.
Status : Received
Published: 2026-10-10T07:16:41.507
Modified: 2026-10-10T07:16:41.507
Link: CVE-2026-3717
No data.
OpenCVE Enrichment
Updated: 2026-10-10T08:30:07Z
Weaknesses