Vulnerabilities > CVE-2022-0442 - Authorization Bypass Through User-Controlled Key vulnerability in Ayecode Userswp

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
ayecode
CWE-639

Summary

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

Vulnerable Configurations

Part Description Count
Application
Ayecode
82