4.3
CVSSv3

CVE-2023-6384

Published: 22/01/2024 Updated: 26/01/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The WP User Profile Avatar WordPress plugin prior to 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar

Vulnerable Product Search on Vulmon Subscribe to Product

wp-eventmanager user profile avatar