Impact
The Avatar plugin contains an insufficient file path validation that lets an authenticated user delete any file on the server. With Subscriber-level access or higher, an attacker can remove critical files such as wp-config.php, which can quickly lead to remote code execution.
Affected Systems
All installations of the Avatar plugin by wonderboymusic up to version 0.1.4 are affected. Any WordPress site running these plugin versions is vulnerable; the issue originates from the plugin's file deletion function.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is a web interface that an authenticated Subscriber-level user can use from the network. Attackers must have at least Subscriber-level access to execute the vulnerable function, after which they can delete arbitrary files on the server. Once critical files such as wp-config.php are removed, remote code execution can be achieved. The CVSS score of 8.1 reflects high severity, while an EPSS score of 7% indicates a moderate likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment
EUVD