The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58624 | The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Oct 2024 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-11T16:36:59.472Z
Reserved: 2023-11-29T16:13:10.279Z
Link: CVE-2023-6384
Updated: 2024-08-02T08:28:21.790Z
Status : Modified
Published: 2024-01-22T20:15:47.507
Modified: 2025-06-11T17:15:39.177
Link: CVE-2023-6384
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD