CVE-2024-9648

Executive Summary

The WP ULike Pro plugin (WordPress) is vulnerable to arbitrary file uploads due to insufficient file type validation in the WP_Ulike_Pro_File_Uploader class in all versions up to 1.9.3. Unauthenticated attackers can upload files with extensions such as .php2, .php6, .php7, .phps, .pht, .phtm, .pgif, .shtml, .phar, .inc, .hphp, .ctp, .module, .html, .svg, potentially enabling XSS or other attacks. Versions up to 1.8.7 are confirmed vulnerable; 1.9.4 is patched. Not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 6.1 (MEDIUM) - Published: 2025-08-28T04:15:41.240 - Last Modified: 2026-09-26T21:10:00.130

Original Description: The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the WP_Ulike_Pro_File_Uploader class in all versions up to, and including, 1.9.3. This makes it possible for unauthenticated attackers to upload limited arbitrary files like .php2, .php6, .php7, .phps, .pht, .phtm, .pgif, .shtml, .phar, .inc, .hphp, .ctp, .module, .html, .svg on the affected site's server which may make make other attacks like Cross-Site Scripting possible. Only versions up to 1.8.7 were confirmed vulnerable, however, the earliest tested version for a patch we have access to is 1.9.4, so we are considering 1.9.4 the patched version.

"In all chaos there is a cosmos, in all disorder a secret order."

— Carl Jung
Source: NVD