MEDIUM
bestwpdeveloper
CVE published 2026-10-10
CVE-2026-3717
The CV Builder – Professional Resume Builder SaaS plugin for WordPress has a vulnerability allowing unauthenticated PNG file uploads due to a missing capability check. This issue affects versions up to and including 1.3.1. The vulnerability allows unauthenticated attackers to upload arbitrary PNG files to the WordPress uploads directory, potentially leading to security issues. Defenders should assess expo [truncated]