Impact
The vulnerability is a missing authorization flaw that allows an attacker to bypass normal access controls within the ProfilePress wp‑user‑avatar module. Because the plugin does not enforce proper permissions on read and possibly write operations, an attacker who can direct crafted requests to the affected endpoints may gain access to private user information or modify profile data. This flaw can lead to confidentiality and integrity breaches for individual users but is limited to the data exposed by the plugin, rather than a full system compromise.
Affected Systems
The issue affects the properfraction ProfilePress WordPress plugin versions up to and including 4.17.3. Any WordPress installation using this plugin in its vulnerable state is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level. EPSS is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is that an attacker sends HTTP requests to the plugin’s endpoints—either as an authenticated site user with sufficient privileges or by exploiting misconfigured access levels—thereby bypassing intended authorization checks.
OpenCVE Enrichment