Vulnerabilities
Vulnerable Software
Onedesigns:  >> One User Avatar  Security Vulnerabilities
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
CVSS Score
5.4
EPSS Score
0.002
Published
2021-10-18
The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack
CVSS Score
6.5
EPSS Score
0.001
Published
2021-10-18


Contact Us

Shodan ® - All rights reserved