Impact
A missing authorization check in the WordPress ProfilePress plugin enables an attacker to view or modify user profile data without proper authentication, potentially exposing confidential personal information or altering user accounts. The vulnerability arises from incorrectly configured access control security levels that allow access to protected resources via the wp‑user‑avatar component. This flaw is classified as a broken access control (CWE‑862).
Affected Systems
The issue affects the ProfilePress WordPress plugin, version 4.17.3 and all earlier releases. Properfraction released the plugin under the ProfilePress name and users running any affected version are at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog at this time. The likely attack vector is a remote web‑based attack that targets the plugin’s public profile URLs; an unauthenticated user or a user with limited privileges can exploit the broken access control to gain unauthorized access to protected profile data.
OpenCVE Enrichment