The WP User Profile Avatar WordPress plugin prior to 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wp-eventmanager user profile avatar |