cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-user-profile-avatar wp-user-profile-avatar

Direction: ascending
Jun 07, 2024

WP User Profile Avatar # CVE-2023-52118

CVE, Research URL

CVE-2023-52118

Date
Feb 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.
Affected versions
Min -, max -.
Status
vulnerable

WP User Profile Avatar # CVE-2023-6384

CVE, Research URL

CVE-2023-6384

Date
Jan 23, 2024
Research Description
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
Affected versions
Min -, max -.
Status
vulnerable

WP User Profile Avatar # CVE-2023-6067

CVE, Research URL

CVE-2023-6067

Date
Apr 15, 2024
Research Description
The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable
Jan 17, 2025

WP User Profile Avatar # CVE-2024-10789

CVE, Research URL

CVE-2024-10789

Date
Jan 16, 2025
Research Description
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers to update the plugins setting which controls access to the functionality via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Jun 23, 2025

WP User Profile Avatar # CVE-2025-49980

CVE, Research URL

CVE-2025-49980

Date
Jun 20, 2025
Research Description
Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Profile Avatar: from n/a through 1.0.6.
Affected versions
Min -, max -.
Status
vulnerable