VYPR

Wp User Profile Avatar

by WordPress

Source repositories

CVEs (4)

  • CVE-2025-49980MedJun 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6.

  • CVE-2024-10789MedJan 16, 2025
    risk 0.28cvss 4.3epss 0.00

    The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers to update the plugins setting which controls access to the functionality via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

  • CVE-2023-6067Apr 15, 2024
    risk 0.00cvss epss 0.00

    The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

  • CVE-2023-6384Jan 22, 2024
    risk 0.00cvss epss 0.00

    The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar