Vulnerabilities and security researches forwp-user-profile-avatar wp-user-profile-avatar
Direction: descendingJun 23, 2025
WP User Profile Avatar # CVE-2025-49980
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 20, 2025
- Research Description
- Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Profile Avatar: from n/a through 1.0.6.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jan 17, 2025
WP User Profile Avatar # CVE-2024-10789
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2025
- Research Description
- The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers to update the plugins setting which controls access to the functionality via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 07, 2024
WP User Profile Avatar # CVE-2023-52118
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 01, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WP User Profile Avatar # CVE-2023-6384
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 23, 2024
- Research Description
- The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WP User Profile Avatar # CVE-2023-6067
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 15, 2024
- Research Description
- The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected versions
-
Min -, max -.
- Status
-
vulnerable