Vulnerabilities > WP Eventmanager > User Profile Avatar

DATE CVE VULNERABILITY TITLE RISK
2024-01-22 CVE-2023-6384 Authorization Bypass Through User-Controlled Key vulnerability in Wp-Eventmanager User Profile Avatar
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
network
low complexity
wp-eventmanager CWE-639
4.3