---
id: CVE-2024-9648
title: >-
  The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads
  due to insufficient file type validation in the WP_Ulike_Pro_File_Uploader
  class in all versions up to, and including, 1.9.3
summary: >-
  The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads
  due to insufficient file type validation in the WP_Ulike_Pro_File_Uploader
  class in all versions up to, and including, 1.9.3. This makes it possible for
  unauth…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-434
published: '2025-08-28'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-9648'
references:
  - url: 'https://wpulike.com/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/9b86d9ea-b842-4492-82e4-dd979fbe70cf?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00205
epssPercentile: 0.09388
ingestedAt: '2026-09-26T21:38:01.482Z'
---

## Overview

The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the WP_Ulike_Pro_File_Uploader class in all versions up to, and including, 1.9.3. This makes it possible for unauthenticated attackers to upload limited arbitrary files like .php2, .php6, .php7, .phps, .pht, .phtm, .pgif, .shtml, .phar, .inc, .hphp, .ctp, .module, .html, .svg on the affected site's server which may make make other attacks like Cross-Site Scripting possible. Only versions up to 1.8.7 were confirmed vulnerable, however, the earliest tested version for a patch we have access to is 1.9.4, so we are considering 1.9.4 the patched version.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
