VYPR
Unrated severityNVD Advisory· Published Jan 22, 2024· Updated Jun 11, 2025

WP User Profile Avatar < 1.0.1 - Author+ Avatar Deletion/Update via IDOR

CVE-2023-6384

Description

The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.