Impact
The Avatar plugin contains an insecure direct object reference that allows an attacker to bypass incorrectly configured access control levels by supplying a user-controlled key. This flaw can enable unauthorized retrieval or modification of avatar images and potentially expose sensitive user data. The vulnerability is an Authorization Bypass through User-Controlled Key, categorized as CWE-639.
Affected Systems
The flaw exists in the WordPress Avatar plugin created by Scott Taylor, affecting all installations using version 0.1.4 or earlier. Any WordPress site that has this plugin installed remains vulnerable until it is upgraded past 0.1.4.
Risk and Exploitability
The CVSS score of 4.3 designates moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be web-based, leveraging publicly available plugin interfaces. The weakness permits an attacker to read or modify resources the attacker should not have access to.
OpenCVE Enrichment
EUVD