CVE-2023-6384: WP User Profile Avatar < 1.0.1 - Author+ Avatar Deletion/Update via IDOR
Published Jan 22, 2024
·Updated
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
Affected Software
1 affected component
Wp-eventmanager User Profile Avatar Wordpress<1.0.1
Event History
Jan 22, 2024
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-6384?
CVE-2023-6384 has a medium severity rating as it allows unauthorized users to delete and update avatars.
2
How can I fix CVE-2023-6384?
You can fix CVE-2023-6384 by updating the WP User Profile Avatar plugin to version 1.0.1 or higher.
3
What is the impact of CVE-2023-6384?
The impact of CVE-2023-6384 is that it allows authors to manipulate user avatars without proper authorization.
4
Is CVE-2023-6384 present in older versions of the plugin?
Yes, CVE-2023-6384 affects WP User Profile Avatar versions before 1.0.1.
5
Who is affected by CVE-2023-6384?
Users of the WP User Profile Avatar plugin, particularly those using versions older than 1.0.1, are affected by CVE-2023-6384.