Vulnerabilities (CVE)

Filtered by vendor Wp-eventmanager Subscribe
Filtered by product User Profile Avatar
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6384 1 Wp-eventmanager 1 User Profile Avatar 2024-11-21 N/A 4.3 MEDIUM
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar