VYPR

User Profile Avatar

by Wp Eventmanager

CVEs (1)

  • CVE-2023-6384MedJan 22, 2024
    risk 0.28cvss 4.3epss 0.00

    The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar