Extension WordPress
Vulnérabilités WP User Profile Avatar
Cette page rassemble les failles publiées pour WP User Profile Avatar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP User Profile Avatar
5 fiches
WP User Profile Avatar <= 1.0.6 – Missing Authorization
The WP User Profile Avatar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.6. This makes it possible for authenticated attackers, with…
*-1.0.6
Non indiqué
19/06/2025
WP User Profile Avatar <= 1.0.5 – Cross-Site Request Forgery to Settings Update
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it…
*-1.0.5
1.0.6
15/01/2025
WP User Profile Avatar <= 1.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP User Profile Avatar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.0.1
1.0.3
25/03/2024
WP User Profile Avatar <= 1.0.0 – Authenticated (Author+) Insecure Direct Object Reference to Avatar Deletion/Update
The WP User Profile Avatar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 via the remove_user_avatar and update_user_avatar functions due to missing validation on a user controlled key.…
*-1.0.0
1.0.1
29/12/2023
WP User Profile Avatar <= 1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP User Profile Avatar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.0
1.0.1
28/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.