vulnerability
WordPress Plugin: wp-user-avatar: CVE-2023-41954: Improper Input Validation
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Sep 9, 2023 | May 15, 2025 | Jul 10, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 9, 2023
Added
May 15, 2025
Modified
Jul 10, 2025
Description
The ProfilePress plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 4.13.1 via the 'acceptable_defined_roles' function due to incomplete validation on a user controlled key. This can allow unauthenticated attackers to elevate their privileges to a non-administrator role during user-registration.
Solution
wp-user-avatar-plugin-cve-2023-41954
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.