CVE Database /
CVE-2021-24675
CVE · Medium
CVE-2021-24675 — One User Avatar | User Profile Picture [one-user-avatar] < 2.3.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24675
|
One User Avatar | User Profile Picture [one-user-avatar] < 2.3.7 |
Cross-Site Request Forgery (CSRF) |
Medium
6.5
|
< 2.3.7
|
2.3.7 |
2021-09-20 |
—
|
CVE-2021-24675
The One User Avatar plugin before version 2.3.7 fails to validate CSRF tokens when users update their avatar through pages containing the [avatar_upload] shortcode, allowing attackers to trick authenticated users into changing their profile picture without their knowledge or consent.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings