Description
Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.
Published: 2026-10-09
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to profile data
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to bypass normal access controls within the ProfilePress wp‑user‑avatar module. Because the plugin does not enforce proper permissions on read and possibly write operations, an attacker who can direct crafted requests to the affected endpoints may gain access to private user information or modify profile data. This flaw can lead to confidentiality and integrity breaches for individual users but is limited to the data exposed by the plugin, rather than a full system compromise.

Affected Systems

The issue affects the properfraction ProfilePress WordPress plugin versions up to and including 4.17.3. Any WordPress installation using this plugin in its vulnerable state is susceptible.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk level. EPSS is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is that an attacker sends HTTP requests to the plugin’s endpoints—either as an authenticated site user with sufficient privileges or by exploiting misconfigured access levels—thereby bypassing intended authorization checks.

Generated by OpenCVE AI on October 9, 2026 at 12:01 UTC.

Remediation

Vendor Solution

Update the WordPress ProfilePress plugin to the latest available version (at least 4.17.4).


OpenCVE Recommended Actions

  • Update the ProfilePress plugin to version 4.17.4 or later to remove the missing authorization checks.
  • If an upgrade is not immediately possible, restrict exposure by blocking or disabling the plugin’s publicly accessible endpoints through web‑application firewall rules or network ACLs.
  • Review WordPress user roles and ensure that only users with the "Administrator" or specifically granted permissions can access profile‑related functionalities.

Generated by OpenCVE AI on October 9, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.
Title WordPress ProfilePress plugin <= 4.17.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:16.886Z

Reserved: 2026-09-23T00:18:19.472Z

Link: CVE-2026-96337

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:44.863

Modified: 2026-10-09T10:16:44.863

Link: CVE-2026-96337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:15:05Z

Weaknesses