Vulnerability Details CVE-2023-6384
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-6384
-
cpe:2.3:a:wp-eventmanager:user_profile_avatar:*