One User Avatar | User Profile Picture

The One User Avatar plugin allows WordPress users to use any photo uploaded into their Media Library as an avatar, without the need for extra folders or image editing functions. The plugin also allows users to upload their own default avatar, disable Gravatar avatars, and limit upload file size and image dimensions for Contributors and Subscribers. The plugin is a fork of WP User Avatar v2.2.16 and is distributed under the terms of the GNU GPL.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in One User Avatar | User Profile Picture 2.3.7

    Fixed

    The One User Avatar WordPress plugin before version 2.3.7 had a security issue that allowed people with Contributor level access to do something called ""Stored Cross-Site Scripting attacks"". This ty...

    Read More
  • Input validation vulnerability in One User Avatar | User Profile Picture 2.3.7

    Fixed

    Read More