Vulnerabilities > CVE-2023-6384 - Authorization Bypass Through User-Controlled Key vulnerability in Wp-Eventmanager User Profile Avatar
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |