Description
WordPress Plugin One User Avatar-User Profile Picture is prone to an unspecified vulnerability. No available information exists regarding this issue and it's impact on a vulnerable website. WordPress Plugin One User Avatar-User Profile Picture version 2.3.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9 or latest
References
Related Vulnerabilities
WordPress Plugin GDPR Cookie Consent Security Bypass (1.8.2)
WordPress Plugin Swipe Checkout for Jigoshop Cross-Site Scripting (3.1.0)
WordPress Plugin AceIDE Local File Inclusion (2.6.2)
WordPress 4.0.x Arbitrary File Deletion Vulnerability (4.0 - 4.0.23)
Apache HTTP Server Improper Privilege Management Vulnerability (CVE-2026-24072)