Description
WordPress Plugin UsersWP-Front-end login form, User Registration, User Profile & Members Directory for WP is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently overwrite another users avatar. WordPress Plugin UsersWP-Front-end login form, User Registration, User Profile & Members Directory for WP version 1.2.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.3.1 or latest
References
Related Vulnerabilities
WordPress Plugin Plugin Central Multiple Cross-Site Scripting Vulnerabilities (2.5)
Apache Tomcat CVE-2024-24549 Vulnerability (CVE-2024-24549)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0837)
WordPress Plugin Simple Personal Message SQL Injection (1.0.3)